segfault in GCGraphBuilder::AddNode
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Mozilla Firefox |
Invalid
|
Critical
|
|||
firefox-3.0 (Ubuntu) |
Triaged
|
Medium
|
Unassigned |
Bug Description
Binary package hint: firefox-3.0
Firefox 3 sefaulted on me yet again.
Program received signal SIGSEGV, Segmentation fault.
[Switching to Thread 0xb7dd66c0 (LWP 31377)]
GCGraphBuilder:
at nsCycleCollecto
1287 nsCycleCollecto
in nsCycleCollecto
Current language: auto; currently c++
(gdb) where
#0 GCGraphBuilder:
at nsCycleCollecto
#1 0xb7a3d401 in GCGraphBuilder:
at nsCycleCollecto
#2 0xb728b6b0 in NoteJSChild (trc=0x1af03e10, thing=0xda1d520, kind=0) at nsXPConnect.cpp:744
#3 0xb7d73df9 in JS_CallTracer (trc=0xbfaab950, thing=0xda1d520, kind=0) at jsgc.c:2449
#4 0xb7d89ecc in js_TraceObject (trc=0xbfaab950, obj=0xda1dd60) at jsobj.c:5082
#5 0xb7d73bba in JS_TraceChildren (trc=0xbfaab950, thing=0xda1dd60, kind=0) at jsgc.c:2233
#6 0xb728b770 in nsXPConnect:
at nsXPConnect.cpp:935
#7 0xb7a3cc84 in GCGraphBuilder:
at nsCycleCollecto
#8 0xb7a3cce7 in nsCycleCollecto
at nsCycleCollecto
#9 0xb7a3d795 in nsCycleCollecto
#10 0xb7a3d7d8 in nsCycleCollecto
#11 0xb728c6cc in XPCCycleCollect
at nsXPConnect.cpp:440
#12 0xb7d74d7a in js_GC (cx=0x94ba360, gckind=GC_NORMAL) at jsgc.c:3239
#13 0xb7d5163a in JS_GC (cx=0x94ba360) at jsapi.c:2469
#14 0xb728b950 in nsXPConnect:
#15 0xb7a3d8fa in nsCycleCollecto
at nsCycleCollecto
#16 0xb7a3da39 in nsCycleCollecto
#17 0xb7638f42 in nsJSContext::CC () at nsJSEnvironment
#18 0xb7639012 in nsJSContext:
#19 0xb76393c5 in nsUserActivityO
aTopic=
#20 0xb7a0c9a0 in nsObserverList:
aTopic=
#21 0xb7a0cc6e in nsObserverServi
aTopic=
#22 0xb75627e6 in nsUITimerCallba
at nsEventStateMan
#23 0xb7a34a42 in nsTimerImpl::Fire (this=0x95c1730) at nsTimerImpl.cpp:403
#24 0xb7a34ab7 in nsTimerEvent::Run (this=0xaf6f7938) at nsTimerImpl.cpp:490
#25 0xb7a3256c in nsThread:
at nsThread.cpp:510
#26 0xb7a02f88 in NS_ProcessNextE
#27 0xb79862c4 in nsBaseAppShell::Run (this=0x9274708) at nsBaseAppShell.
#28 0xb781bab8 in nsAppStartup::Run (this=0x92b7620) at nsAppStartup.
#29 0xb7280508 in XRE_main (argc=2, argv=0xbfab3494, aAppData=0x9156830) at nsAppRunner.
#30 0x080491ab in ?? ()
#31 0xb7dee685 in __libc_start_main () from /lib/tls/
#32 0x08048d11 in ?? ()
All threads:
(gdb) thread apply all bt
Thread 259 (Thread 0xae412b90 (LWP 27653)):
#0 0xb80b2430 in __kernel_vsyscall ()
#1 0xb80693a2 in pthread_
#2 0xb7d0bf9e in pt_TimedWait (cv=0xa995204, ml=0xa9951a0, timeout=60000) at ptsynch.c:280
#3 0xb7d0cdc0 in PR_WaitCondVar (cvar=0xa995200, timeout=60000) at ptsynch.c:407
#4 0xb72e6d4a in nsHostResolver:
at nsHostResolver.
#5 0xb72e7412 in nsHostResolver:
#6 0xb7d131e1 in _pt_root (arg=0x18035188) at ptthread.c:221
#7 0xb806550f in start_thread () from /lib/tls/
#8 0xb7eb97ee in clone () from /lib/tls/
Thread 9 (Thread 0xb5b12b90 (LWP 31505)):
#0 0xb80b2430 in __kernel_vsyscall ()
#1 0xb7eaef77 in poll () from /lib/tls/
#2 0xb7d0ed8c in _pr_poll_with_poll (pds=0x9243240, npds=1, timeout=4294967295) at ptio.c:3895
#3 0xb72dda7b in nsSocketTranspo
at nsSocketTranspo
#4 0xb72ddf70 in nsSocketTranspo
at nsSocketTranspo
#5 0xb72de21a in nsSocketTranspo
mayWait=1, depth=1) at nsSocketTranspo
#6 0xb7a3250e in nsThread:
at nsThread.cpp:497
#7 0xb7a02f88 in NS_ProcessNextE
#8 0xb72ddc93 in nsSocketTranspo
at nsSocketTranspo
#9 0xb7a3256c in nsThread:
at nsThread.cpp:510
#10 0xb7a02f88 in NS_ProcessNextE
#11 0xb7a32cd3 in nsThread:
#12 0xb7d131e1 in _pt_root (arg=0x9b1f060) at ptthread.c:221
#13 0xb806550f in start_thread () from /lib/tls/
#14 0xb7eb97ee in clone () from /lib/tls/
Thread 7 (Thread 0xb3002b90 (LWP 31480)):
#0 0xb80b2430 in __kernel_vsyscall ()
#1 0xb8069075 in pthread_
#2 0xb7d0ce39 in PR_WaitCondVar (cvar=0x9c7ee90, timeout=4294967295) at ptsynch.c:405
#3 0xb7d0ceb7 in PR_Wait (mon=0x9594b78, timeout=4294967295) at ptsynch.c:584
#4 0xb7a31791 in nsEventQueue:
at ../../dist/
#5 0xb7a32540 in nsThread:
at nsThread.h:112
#6 0xb7a02f88 in NS_ProcessNextE
#7 0xb7a32cd3 in nsThread:
#8 0xb7d131e1 in _pt_root (arg=0x95961c0) at ptthread.c:221
#9 0xb806550f in start_thread () from /lib/tls/
#10 0xb7eb97ee in clone () from /lib/tls/
Thread 5 (Thread 0xb52f0b90 (LWP 31382)):
#0 0xb80b2430 in __kernel_vsyscall ()
#1 0xb80693a2 in pthread_
#2 0xb7d0bf9e in pt_TimedWait (cv=0x91cb3e4, ml=0x91dbc38, timeout=2328) at ptsynch.c:280
#3 0xb7d0cdc0 in PR_WaitCondVar (cvar=0x91cb3e0, timeout=2328) at ptsynch.c:407
#4 0xb7a354bc in TimerThread::Run (this=0x91dbdd8) at TimerThread.cpp:345
#5 0xb7a3256c in nsThread:
at nsThread.cpp:510
#6 0xb7a02f88 in NS_ProcessNextE
#7 0xb7a32cd3 in nsThread:
#8 0xb7d131e1 in _pt_root (arg=0x92fca60) at ptthread.c:221
#9 0xb806550f in start_thread () from /lib/tls/
#10 0xb7eb97ee in clone () from /lib/tls/
Thread 4 (Thread 0xb4987b90 (LWP 31386)):
#0 0xb80b2430 in __kernel_vsyscall ()
#1 0xb8069075 in pthread_
#2 0xb7d0ce39 in PR_WaitCondVar (cvar=0x9605578, timeout=4294967295) at ptsynch.c:405
#3 0xb783b266 in nsSSLThread::Run (this=0x96054f0) at nsSSLThread.cpp:964
#4 0xb783ab9a in nsPSMBackground
at nsPSMBackground
#5 0xb7d131e1 in _pt_root (arg=0x96055b8) at ptthread.c:221
#6 0xb806550f in start_thread () from /lib/tls/
#7 0xb7eb97ee in clone () from /lib/tls/
Thread 3 (Thread 0xb391ab90 (LWP 31387)):
#0 0xb80b2430 in __kernel_vsyscall ()
#1 0xb8069075 in pthread_
#2 0xb7d0ce39 in PR_WaitCondVar (cvar=0x9605748, timeout=4294967295) at ptsynch.c:405
#3 0xb783c2fe in nsCertVerificat
at nsCertVerificat
#4 0xb783ab9a in nsPSMBackground
at nsPSMBackground
#5 0xb7d131e1 in _pt_root (arg=0x9605788) at ptthread.c:221
#6 0xb806550f in start_thread () from /lib/tls/
#7 0xb7eb97ee in clone () from /lib/tls/
Thread 1 (Thread 0xb7dd66c0 (LWP 31377)):
#0 GCGraphBuilder:
at nsCycleCollecto
#1 0xb7a3d401 in GCGraphBuilder:
at nsCycleCollecto
#2 0xb728b6b0 in NoteJSChild (trc=0x1af03e10, thing=0xda1d520, kind=0) at nsXPConnect.cpp:744
#3 0xb7d73df9 in JS_CallTracer (trc=0xbfaab950, thing=0xda1d520, kind=0) at jsgc.c:2449
#4 0xb7d89ecc in js_TraceObject (trc=0xbfaab950, obj=0xda1dd60) at jsobj.c:5082
#5 0xb7d73bba in JS_TraceChildren (trc=0xbfaab950, thing=0xda1dd60, kind=0) at jsgc.c:2233
#6 0xb728b770 in nsXPConnect:
at nsXPConnect.cpp:935
#7 0xb7a3cc84 in GCGraphBuilder:
at nsCycleCollecto
#8 0xb7a3cce7 in nsCycleCollecto
at nsCycleCollecto
#9 0xb7a3d795 in nsCycleCollecto
#10 0xb7a3d7d8 in nsCycleCollecto
#11 0xb728c6cc in XPCCycleCollect
at nsXPConnect.cpp:440
#12 0xb7d74d7a in js_GC (cx=0x94ba360, gckind=GC_NORMAL) at jsgc.c:3239
#13 0xb7d5163a in JS_GC (cx=0x94ba360) at jsapi.c:2469
#14 0xb728b950 in nsXPConnect:
#15 0xb7a3d8fa in nsCycleCollecto
at nsCycleCollecto
#16 0xb7a3da39 in nsCycleCollecto
#17 0xb7638f42 in nsJSContext::CC () at nsJSEnvironment
#18 0xb7639012 in nsJSContext:
#19 0xb76393c5 in nsUserActivityO
aTopic=
#20 0xb7a0c9a0 in nsObserverList:
aTopic=
#21 0xb7a0cc6e in nsObserverServi
aTopic=
#22 0xb75627e6 in nsUITimerCallba
at nsEventStateMan
#23 0xb7a34a42 in nsTimerImpl::Fire (this=0x95c1730) at nsTimerImpl.cpp:403
#24 0xb7a34ab7 in nsTimerEvent::Run (this=0xaf6f7938) at nsTimerImpl.cpp:490
#25 0xb7a3256c in nsThread:
at nsThread.cpp:510
#26 0xb7a02f88 in NS_ProcessNextE
#27 0xb79862c4 in nsBaseAppShell::Run (this=0x9274708) at nsBaseAppShell.
#28 0xb781bab8 in nsAppStartup::Run (this=0x92b7620) at nsAppStartup.
#29 0xb7280508 in XRE_main (argc=2, argv=0xbfab3494, aAppData=0x9156830) at nsAppRunner.
#30 0x080491ab in ?? ()
#31 0xb7dee685 in __libc_start_main () from /lib/tls/
#32 0x08048d11 in ?? ()
Changed in firefox: | |
status: | Unknown → New |
Changed in firefox-3.0: | |
importance: | Undecided → Medium |
status: | Incomplete → Triaged |
Changed in firefox: | |
status: | New → Confirmed |
Changed in firefox: | |
importance: | Unknown → Critical |
Changed in firefox: | |
status: | Confirmed → Invalid |
do you have a way to reproduce this?