Closed
      
        Bug 327524
      
      
        Opened 19 years ago
          Closed 19 years ago
      
        
    
  
Crash when using crypto.generateCRMFRequest(document.documentElement);    
    Categories
(Core :: Security: PSM, defect)
Tracking
()
        RESOLVED
        FIXED
        
    
  
People
(Reporter: martijn.martijn, Assigned: KaiE)
Details
(4 keywords, Whiteboard: [sg:dupe 330900])
Attachments
(1 file)
| 267 bytes,
          text/html         | Details | 
I'm filing this mainly as security sensitive, because I got the idea from bug 327126, but I guess it's probably not security sensitive.
See upcoming testcase, which crashes current trunk Mozilla build. 
It also crashes Mozilla1.7.12, so no (recent) regression.
Talkback ID: TB15160940G
0x00110111
js_GetSlotThreadSafe  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jslock.c, line 592]
JS_GetPrivate  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsapi.c, line 2153]
nsScriptSecurityManager::GetFramePrincipal  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/caps/src/nsScriptSecurityManager.cpp, line 2019]
nsScriptSecurityManager::GetPrincipalAndFrame  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/caps/src/nsScriptSecurityManager.cpp, line 2050]
nsScriptSecurityManager::GetSubjectPrincipal  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/caps/src/nsScriptSecurityManager.cpp, line 2092]
nsScriptSecurityManager::doGetSubjectPrincipal  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/caps/src/nsScriptSecurityManager.cpp, line 1690]
nsScriptSecurityManager::SubjectPrincipalIsSystem  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/caps/src/nsScriptSecurityManager.cpp, line 1725]
nsContentUtils::IsCallerChrome  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/content/base/src/nsContentUtils.cpp, line 1016]
PresShell::HandleEventInternal  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/layout/base/nsPresShell.cpp, line 6051]
PresShell::HandleEvent  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/layout/base/nsPresShell.cpp, line 5858]
nsViewManager::HandleEvent  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/view/src/nsViewManager.cpp, line 1725]
nsViewManager::DispatchEvent  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/view/src/nsViewManager.cpp, line 1678]
HandleEvent  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/view/src/nsView.cpp, line 175]
nsWindow::DispatchEvent  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/widget/src/windows/nsWindow.cpp, line 1036]
nsWindow::DispatchFocus  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/widget/src/windows/nsWindow.cpp, line 6068]
nsWindow::ProcessMessage  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/widget/src/windows/nsWindow.cpp, line 4640]
nsWindow::WindowProc  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/widget/src/windows/nsWindow.cpp, line 1225]
USER32.dll + 0x27b17 (0x77d37b17)
USER32.dll + 0x2cdce (0x77d3cdce)
USER32.dll + 0x459d (0x77d1459d)
USER32.dll + 0x47b4 (0x77d147b4)
ntdll.dll + 0x2589f (0x77f6589f)
USER32.dll + 0x96ce (0x77d196ce)
PeekKeyAndIMEMessage  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/widget/src/windows/nsAppShell.cpp, line 91]
nsAppShell::Run  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/widget/src/windows/nsAppShell.cpp, line 128]
nsAppStartup::Run  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/toolkit/components/startup/src/nsAppStartup.cpp, line 162]
main  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/browser/app/nsBrowserApp.cpp, line 61]
kernel32.dll + 0x1eb69 (0x77e5eb69)
| Reporter | ||
| Comment 1•19 years ago
           | ||
| Comment 2•19 years ago
           | ||
I get a similar stack, except in nsScriptSecurityManager::GetFramePrincipal calling JS_GetFrameFunctionObject.
Bug 330900 may be related.
| Assignee | ||
| Updated•19 years ago
           | 
Assignee: dveditz → kengert
Component: Security → Security: PSM
QA Contact: toolkit
| Reporter | ||
| Comment 4•19 years ago
           | ||
Doesn't crash anymore in 2006-03-26 build, most likely fixed by bug 330900.
Status: NEW → RESOLVED
Closed: 19 years ago
Resolution: --- → FIXED
| Updated•19 years ago
           | 
Whiteboard: [sg:dupe 330900]
| Updated•19 years ago
           | 
Group: security
| Updated•17 years ago
           | 
Keywords: fixed1.8.0.4, 
          
            fixed1.8.1
| Comment 5•16 years ago
           | ||
crash test landed
http://hg.mozilla.org/mozilla-central/rev/b0a63ee1ed5f
Flags: in-testsuite+
          You need to log in
          before you can comment on or make changes to this bug.
        
 
 
Description
•