QA/Topcrashes/Archive

From MozillaWiki
< QA‎ | Topcrashes
Jump to: navigation, search

This is an archive of tracked topcrashes in previous releases.

Current topcrashes being tracked 3.0.7

Summary

Date -

Queries

List

# bug stack where status
1 bug 469366 nsSubDocumentFrame::Reflow layout wasn't in the top 100 before
2 bug 435779 PostMessageEvent::Run() dom patch in bug; wasn't a topcrash before so we didn't take the patch in an earlier release
3 bug 444930 nsIFrame::GetAncestorWithView() acrobat reader fixed in a new version of the plugin
4 bug 467167 _PR_MD_SEND nspr possibly caused by an add-on, otherwise nspr
5 none yet user32.dll@0x11911 plugins multiple plugins including S4PLUGIN.DLL, WinampTBPlayer.dll, MyGlobalSearch spyware (most seem like those three)
6 bug 470487 nsWindow::GetParentWindow()
7 bug 427715 NSSRWLock_LockRead_Util psm (maybe nss) been a topcrash forever; not clear what's causing it
8 msvcrt.dll@0x37c89
9 bug 459531 libobjc.A.dylib@0x15688
10 nsBaseWidget::Destroy()
11 @0x0 no single crash
12 bug 437449 nsCycleCollector::MarkRoots(GCGraphBuilder&)  ??
13 bug 466024 nsStyleSet::AddImportantRules(nsRuleNode*, nsRuleNode*) maybe caused by extensions?
14 GoogleDesktopMozilla.dll@0x5500 google desktop
15 PL_DHashTableOperate
16 arena_run_reg_alloc
17 ntdll.dll@0x43387
18 msvcrt.dll@0x1226a
19 RaiseException
20 kernel32.dll@0x12aeb
26 GoogleDesktopMozilla.dll@0x5512 Google Desktop
32 fastzero_I
96 NPSWF32.dll@0x1a7640 flash Windows-specific

Current topcrashes being tracked 3.1b3

Summary

Date - Summary

Queries

List

(Using the last week query.

# bug stack where status
1 bug 482687 nsXULWindow::SavePersistentAttributes() xul fix checked in for beta 4
2 bug 468727 nsHTMLTextFieldAccessible::GetStateInternal(unsigned int*, unsigned int*) a11y fix checked in for beta 4
3 bug 481444 LeaveTree js fix checked in for beta 4
4 nanojit::LIns::isTramp()
5 nsGlobalWindow::RunTimeout(nsTimeout*)
6 bug 470487 nsWindow::GetParentWindow()
7 nssutil3.dll@0x34c0 desc
8 dtoa desc
9 memmove desc
10 js_SynthesizeFrame desc
11 _PR_MD_SEND desc
12 nsCOMPtr_base::assign_assuming_AddRef(nsISupports*) desc
13 nsBaseWidget::Destroy() desc
14 nsJARChannel::OnStartRequest(nsIRequest*, nsISupports*) desc
15 arena_dalloc desc
16 msvcrt.dll@0x37c89 desc
17 nsGlobalWindow::InsertTimeoutIntoList(nsTimeout* desc
18 @0x0 desc
19 nsGlobalWindow::ResumeTimeouts(int) desc
20 JS_GetStringChars desc

Current topcrashes being tracked 3.1b2

Summary

19 Dec 2008 - Starting to analyze crashes and assemble the list.

Queries

List

(Using the last week query.)

"new" indicates new to the topcrash list in beta2

# bug stack where status
1 0x0 general crash; no one topcrash
2 (new) bug 467007 nanojit::LirBufWriter::insLink(nanojit::LOpcode, nanojit::LIns*) fix is on the branch and verified1.9.1
3 (new) bug 470485 nanojit::LirBufWriter::insImm(int) could be fixed by bug 467007
4 (new) bug 470487 nsWindow::GetParentWindow()
5 (new) bug 470492 nanojit::LIns::targetAddr() patch on the TM branch, but may need more work
6 (new) bug 470494 or bug 466659 dtoa maybe flash?
7 (new) maybe a variation of bug 470487 nsBaseWidget::Destroy()
8 formerly 16 bug 458667 OfficeAV.dll@0x5606 symantec is pushing a patch for this
10 formerly 15 bug 458961 libobjc.A.dylib@0x24c7 cocoa widgets mac-only, potential patch in bug; ppc version is #10
11 (new) bug 470892 nanojit::LIns::deref(int) graydon's latest merge from adobe's nj repository may have fixed
12 formerly 5 bug 424663 imm32.dll@0x3e24 windows widget code happens with chinese ime
13 (back?) bug 434752 and bug bug 420678 arena_dalloc_small graveyard for incompat binary addons and plugins need to investigate for possible round of 3.1 blocklisting
15 (new) bug 470758 JS_GetMethodById easy to reproduce xp. Regression from 7 or 8/11/2008 is now fixed in 1.9.1
17 formerly 6 bug 424663 CalcCharacterPositionAtoW windows widget code happens with chinese ime
59 formerly 7 bug 462778 JS_TraceChildren js engine (xpconnect?) patch landed for b2
47 formerly 9 bug 444446 memcpy sqlite mostly caused by sqlite functions; should be fixed in b2

Current topcrashes being tracked 3.0.6

Summary

Date -

Queries

List

# bug stack where status
1 bug 435779 PostMessageEvent::Run() dom patch in bug; wasn't a topcrash before so we didn't take the patch in an earlier release
2 none yet user32.dll@0x11911 plugins multiple plugins including S4PLUGIN.DLL, WinampTBPlayer.dll, MyGlobalSearch spyware (most seem like those three)
3 bug 444930 nsIFrame::GetAncestorWithView() acrobat reader fixed in a new version of the plugin
4 bug 427715 NSSRWLock_LockRead_Util psm (maybe nss) been a topcrash forever; not clear what's causing it
5 bug 467167 _PR_MD_SEND nspr possibly caused by an add-on, otherwise nspr
6 msvcrt.dll@0x37c89
7 bug 470487 nsWindow::GetParentWindow()
8 GoogleDesktopMozilla.dll@0x5500 google desktop
9 libobjc.A.dylib@0x15688
10 NPSWF32.dll@0x1a7640 flash Windows-specific
11 arena_run_reg_alloc
12 kernel32.dll@0x12aeb
13 bug 437449 nsCycleCollector::MarkRoots(GCGraphBuilder&)  ??
14 bug 466024 nsStyleSet::AddImportantRules(nsRuleNode*, nsRuleNode*) maybe caused by extensions?
15 @0x0 no single crash
16 RaiseException
17 msvcrt.dll@0x1226a
18 fastzero_I
19 ntdll.dll@0x43387
20 GoogleDesktopMozilla.dll@0x5512 Google Desktop
26 nsBaseWidget::Destroy()

Current topcrashes being tracked 3.1b1

Summary

7 Nov 2008 - Fix for #1 landed in b2. Potential fix for #2, #4, #7, and #8 (maybe #11) landed for b2. Some contrast applies from previous update. Also had a potential fix land for #10 and #15 for b2.

2 Nov 2008 - Top crashes are spread mostly between imagelib (#1), JS (#2, #4, #7, #8), and widget code (Windows: #5, #6 + Mac: #11, #19). Only one clear external crash in the top 10, caused by Norton. This contrasts the top crash list for Firefox 3.0.3 where 6/10 are from external factors.

Queries

List

(Using the last week query.)

# bug stack where status
1 bug 441563 imgRequest::NotifyProxyListener(imgRequestProxy*) imagelib patch landed for b2
2 bug 462778 0x20202020 js engine (xpconnect?) patch landed for b2
3 0x0 general crash; no one topcrash
4 bug 462778 js_GetGCThingTraceKind js engine (xpconnect?) patch landed for b2
5 bug 424663 imm32.dll@0x3e24 windows widget code happens with chinese ime
6 bug 424663 CalcCharacterPositionAtoW windows widget code happens with chinese ime
7 bug 462778 JS_TraceChildren js engine (xpconnect?) patch landed for b2
8 bug 462778 xpsp2res.dll@0x202113 js engine (xpconnect?) patch landed for b2
9 bug 444446 memcpy sqlite mostly caused by sqlite functions; should be fixed in b2
10 bug 458961 0xfffeff20 cocoa widgets mac-only, potential patch in bug; intel version is #15
11 xpsp2res.dll@0x202020 potentially the same as bug 462778?
15 bug 458961 libobjc.A.dylib@0x24c7 cocoa widgets mac-only, potential patch in bug; ppc version is #10
16 bug 458667 OfficeAV.dll@0x5606

Current topcrashes being tracked 3.0.5

Summary

Date -

Queries

List

(Using the last week query.)

# bug stack where status
1 @0x0 no single crash
2 nsObjCExceptionLogAbort cocoa widgets all exceptions crash Firefox on Mac; slowly fixing some of them
3 bug 427715 NSSRWLock_LockRead_Util  ?? firefox is calling nss functions before initializing it. need to find out where
4 bug 444930 nsIFrame::GetAncestorWithView() happens for some users when downloading a pdf
5 bug 453927, bug 459850 JS_RestoreFrameChain extension caused by DTToolbar.dll; needs to be blocklisted
6 bug 458667 OfficeAV.dll@0x5606 Norton caused by Norton AV checking on download
7 bug 436302, bug 457970 strchr extensions old versions of binary extensions not properly updated for firefox3; possibly worth blocklisting
8 bug 453927, bug 459850 JS_BeginRequest extension caused by DTToolbar.dll; needs to be blocklisted
9 nsWindow::GetParentWindow() new topcrash
10 bug 466021 nsStyleSet::AddImportantRules(nsRuleNode*, nsRuleNode*) style system Windows-only, doesn't appear to be caused by an extension
11 bug 458961 0xfffeff20 cocoa widgets Mac-only; intel version is #16
12 bug 459531, bug 465623 libobjc.A.dylib@0x15688 gfx mac-only; unclear what triggers either crash
13 arena_run_reg_alloc
14 nsXULDocument::OnStreamComplete new topcrash?
15 msvcrt.dll@0x37c89
16 bug 458961 libobjc.A.dylib@0x24c7 cocoa widgets Mac-only; ppc version is #11
17 RaiseException
18 kernel32.dll@0x12aeb
19 ntdll.dll@0x43387
20 PL_DHashTableOperate
21 bug 434403 nsDocShell::SetupNewViewer(nsIContentViewer*) trojan caused by a trojan
22 PostMessageEvent::Run()
23 NPSWF32.dll@0x9f321 flash needs triage
24 strstr
25 @0x300d508c
26

Current topcrashes being tracked 3.0.4

Summary

21 Nov 2008 - Initial list for 3.0.4. Investigating various top crashes.

Queries

List

(Using the last week query.)

# bug stack where status
1 bug 427715, bug 465974 NSSRWLock_LockRead_Util  ?? firefox is calling nss functions before initializing it. need to find out where
2 @0x0 no single crash
3 nsObjCExceptionLogAbort cocoa widgets all exceptions crash Firefox on Mac; potential fix landed, didn't work (bug 442245)
4 bug 453927, bug 459850 JS_RestoreFrameChain extension caused by DTToolbar.dll; needs to be blocklisted
5 bug 444930 nsIFrame::GetAncestorWithView() happens for some users when downloading a pdf
6 bug 453927, bug 459850 JS_BeginRequest extension caused by DTToolbar.dll; needs to be blocklisted
7 bug 458667 OfficeAV.dll@0x5606 Norton caused by Norton AV checking on download
8 bug 436302, bug 457970 strchr extensions old versions of binary extensions not properly updated for firefox3; possibly worth blocklisting
9 bug 460744 @0x300d4eea flash caused by outdated Flash plugin?
10 bug 458961 0xfffeff20 cocoa widgets Mac-only; intel version is #15
11 NPSWF32.dll@0x92668 flash needs triage
12 bug 466021 nsStyleSet::AddImportantRules(nsRuleNode*, nsRuleNode*) style system Windows-only, doesn't appear to be caused by an extension
13 ntdll.dll@0x43387 needs triage
14 NPSWF32.dll@0x880ff flash needs triage
15 bug 458961 libobjc.A.dylib@0x24c7 cocoa widgets Mac-only; ppc version is #10
16 0x300d508c needs triage; windows-only
17 NPSWF32.dll@0x14f770 flash needs triage
18 bug 459531, bug 465623 libobjc.A.dylib@0x15688 gfx mac-only; unclear what triggers either crash
19 arena_run_reg_alloc
20 bug 444446 memcpy sqlite fixed in 3.0.5 hopefully
21 0x1 no one crash
22 PL_DHashTableOperate needs triage
23 RaiseException
24 bug 437449 nsCycleCollector::MarkRoots(GCGraphBuilder&) needs triage
25 bug 434403 nsDocShell::SetupNewViewer(nsIContentViewer*) trojan caused by a trojan

Current topcrashes being tracked 3.0pre

# bug stack where status
#8 bug 433525 nsNavHistoryQueryResultNode::IsContainersQuery() places no status update
#9 bug 427715 NSSRWLock_LockRead_Util nss possible patch in hand, awaiting review
#36 (#10 on mac) bug 433432 -[ChildView processPluginKeyEvent:] cocoa widgets possible patch in hand
bug 426499 DrawTheMenu(MenuSelectData*, __CFArray**, unsigned char, unsigned char*) cocoa widgets fixed 2008-04-28
bug 429442 nsJSIID::HasInstance, XPCNativeSet::FindInterfaceWithIID fixed 2008-05-06
bug 430624 nsDocShellEditorData::DetachFromWindow() fixed 2008-05-02
bug 421217 JS_SetPrivate silverlight plugin or scriptable plugin API polvi made contact with Silverlight developers -fix coming
bug 426369 _cairo_win32_surface_create_similar_internal fixed in 2008-04-02 builds
bug 426208 nsAccUtils::IsXLink fixed in 2008-04-01 builds
bug 426392 nsXULPopupManager::ShowPopupCallback fixed in 2008-04-04 builds

topcrashes being tracked for b5

# bug stack where status
started 3 now #12 bug 425592 UniscribeItem::IsGlyphMissing
4 bug 419127 free called by _releasevariantvalue yahoo messenger incompat
5 bug 427837 and/or bug 400291 and/or bug 426499 objc_msgSend
6 bug 420678 arena_dalloc_small - free - XPCWrappedNative::CallMethod(XPCCallContext has a patch
7 bug 422823 nsObjCExceptionLogAbort(NSException* needs to be broken into several bugs now.
10 bug 426987 nsSubDocumentFrame::Reflow has testcase and fix
11 bug 427934 @0x20202020 looks like its new in beta5
12 bug 428726 @memcpy related to flaky connection?
35 bug 427108 extent_tree_ad_s_RB_REMOVE jemalloc.c:1986

Current topcrashes being tracked b5-pre

# bug stack where status
bug 424163 sqlite3BitvecSet fixed in 2008-03-21 builds
1 bug 423446 npdsplay.dll,UserCallWinProcCheckWow,@0x300bf8c3 with plugins on reload or back and forward fixed in 2008-03-20 builds
bug 423475 cert_pkixSetParam fixed in 2008-03-18 builds
bug 424165 FontEntry::Release, gfxWindowsPlatform::FindFontForCharProc, gfxWindowsPlatform::FindFontEntry fixed in 2008-03-22 builds
bug 424566 Compare fixed in 2008-03-23 builds
bug 422827 -- needs additional bug filed objc_msgSend

Current topcrashes being tracked for beta 4

data for beta4 crashes in the last week

# bug stack where status
1 bug 422018 googletoolbar.dll@0x4b2f libgoogletoolbar.dylib@0x4fbd google toolbar? core? google has an update coming for fx3 that will eliminate the crash.
2, 3, 14, 17 bug 416521 (70%), bug 422024 (20%) RtlEnterCriticalSection, free, arena_dalloc_small, ntdll.dll@0x42e7b this is what shows up when we crash in free() bug 422024 is related to scriptable plugin API. FreeDownLoadManager (one of the problematic extensions) is now blocked
4 bug 382356 MultiByteToWideChar always has to do with idmmzcc.dll Internet Download Manager which now has been blocked
5, 15 bug 421303 jsds_ScriptHookProc Fixed for 2008-03-11 builds
6 bug 380015 nsFrame::BoxReflow due to Firefox 3 installs that mix in components from Firefox 2 primary cause fixed in 2008-03-19 builds
7 bug 421217 JS_SetPrivate silverlight plugin or scriptable plugin API polvi made contact with Silverlight developers -fix coming
8, 13 bug 419695 js_GetGCThingTraceKind, JS_CallTracer, JS_TraceChildren crashing on yahoo mail (maybe not all of the JS_CallTracer crashes, though?) one bug fixed for 2008-03-12 builds, need to file more on remaining problems
9 bug 391311 nsChromeRegistry::CheckForNewChrome backup/restore creates inconsistent state in between compatibility.ini and compreg.dat/xpti.dat and this leads to crash
10 bug 418384 ClientData::GetOtlTable has testcase (requires particular font)
11 bug 418381 HashString looks like a start-up crash. not much to go on for further investigation. running the mini-dump might help.
12 bug 422467 piclens.dll the piclens extension the extension doesn't appear to be compatible, or marked as such (although it can't be installed due to not providing secure updates), and the crash is what you'd expect from using a binary extension with incompatible interface changes. Is this entirely from people overriding extension compat? -- piclens develpers contacted 3/12
16 0x0 didn't find any common patterns in sample of ten; this is mixed crashes (although about half the stacks are useless) -David Baron
18 bug 418382 UniscribeItem::SaveGlyphs(gfxTextRun*) core
29 bug 423592 npLegitCheckPlugin.dll@0x14e09 incompatible version of the .dll?
1 on mac bug 422823 nsObjCExceptionLogAbort Our code calling native widgets? The patches in bug 419668 and bug 409615 are expected to fix the file picker issues, which are believed to account for most nsObjCExceptionLogAbort crashes.
19 (2 on mac) bug 421294 DocumentViewerImpl::GetCopyable fixed for 2008-03-07 builds
6 on mac bug 422827 libobjc.A.dylib@0x146e8 via nsMenuX::RemoveAll Core: looks like crash on quit
75 bug 423157 google[@ gears.dll@0xf00fb] users overiding extensions checks and crash using google reader keep an eye out for ramp up
11 on mac bug 422546 nsEditor::nsEditor fixed for 2008-03-14 builds

Current topcrashes being tracked for beta 3

Topcrashers for beta3 are currently considered "old". We need to re-track for beta4. I'm using this "old" data as sample data to see if what format works.

# bug stack where status
4 405357 jpinscp.dll@0xcf45 java plugin still around in b4 @ #10 ranking
6 418378 nsGlobalWindow::SaveWindowState(nsISupports**) core not seen since feb 8-9 2008
7 391311 nsChromeRegistry::CheckForNewChrome core still around in b4 @ #25 ranking
9 418382 UniscribeItem::SaveGlyphs(gfxTextRun*) core still around in b4 @ #92
11 418381 HashString(nsAString_internal const&) core still round in b4 @ #11
14 418379 nsNavHistoryFolderResultNode::FindChildById(__int64, unsigned int*) core not in b4 top 100
26 418384 ClientData::GetOtlTable(long, unsigned char const**, unsigned long*) core still around in b4 @ #31
37 380015 nsFrame::BoxReflow(nsBoxLayoutState&, nsPresContext*, nsHTMLReflowMetrics&, nsIRenderingContext*, int, int, int, int, int) core still around in b4 @ #17