Issue metadata
Sign in to add a comment
|
Random chrome crashes in libxml due to component updater
Reported by
drb...@vitalitymedicalgroup.com,
Mar 16 2016
|
||||||||||||||||||||||
Issue descriptionChrome Version: 49.0.2623.87 Operating System: e.g., "Windows 7", "Mac OSX 10.6" URL (if applicable) where crash occurred: Can you reproduce this crash? no What steps will reproduce this crash? (or if it's not reproducible, what were you doing just before the crash)? 1.any web browsing it will randomly crash after 1-2 minutes of usage 2. 3. *Please note that issues filed with no information filled in above will be marked as WontFix* ****DO NOT CHANGE BELOW THIS LINE**** report_id:c38ca27400000000
,
Mar 21 2016
,
Mar 22 2016
,
Mar 22 2016
,
Apr 12 2016
This crash is expected not to occur in M50. In M50 we have introduced a mechanism to verify the integrity of the XML response before it is handed over to libxml for parsing. I believe that the cause of this crash is parsing corrupt XML content. Parsing corrupt XML content in M49 builds and less is a known issues. It has been partially mitigated by using HTTPS for component update checks. For all versions of Chrome, there are 67 crashes at this call site, most of them having the component updater on the stack: https://crash.corp.google.com/browse?q=product.name%3D%27Chrome%27%20AND%20custom_data.ChromeCrashProto.ptype%3D%27browser%27%20OMIT%20RECORD%20IF%20SUM(CrashedStackTrace.StackFrame.FunctionName%3D%27xmlParseVersionInfo%27)%20%3D%200&ignore_case=false&enable_rewrite=true&omit_field_name=CrashedStackTrace.StackFrame.FunctionName&omit_field_value=xmlParseVersionInfo&omit_field_opt=%3D#samplereports:5,clientid:20 No similar crash occurs in M50 or higher. The crashes are clustered around a few client ids only, but there is a long tail of crashes that indicates that several client can hit this code path. CLIENT IDdremel Choose 1 e2d6c6d7-5400-49f2-92f6-77ad301a9fa0 40.30% 27 2 9b6a8fd6-0e19-42a2-8c67-788ec4fe2de4 14.93% 10 3 12b72eab-e7f3-42a2-8296-e6a816beff7c 8.96% 6 4 D9796EFCB4334C8CA0234AC12AC01738 5.97% 4 5 ebe409d3-34bb-4867-bbb8-49c3fae7cf34 4.48% 3 6 A83A312D386244BABA49D44C810A45CE 4.48% 3 7 4D890DF00B9F4331AE4543FBB5A87A45 4.48% 3 8 0E6EAB27376C4E5E8EECFB0FC243DA35 1.49% 1 9 67d8cbe5-b6bc-4891-99c4-08eee60b521b 1.49% 1 10 0decb081-efbc-45c2-b0a5-1ef0a74a1a2b 1.49% 1 11 c71b1b38-ba54-43d2-8f7b-befc38b7941f 1.49% 1 12 37C7596CAC37494EAF7C8D47E3F60948 1.49% 1 13 6F79CC255E3048BF8286A433C4134736 1.49% 1 14 2EA06D24CDC34B1FB7FF3A96A452833F 1.49% 1 15 13419CAE291F4B7ABA428E47FF180AA4 1.49% 1 16 E0C59535B5584E618D3FF982FFA5F2FD 1.49% 1 17 449A476D9D164D2A96C28F8DD390CBCE 1.49% 1 18 3331A07E32744A7F8377B0C46991F2DC 1.49% 1 +10-10 1000 limitTotal: 100.00% 67
,
Jul 20 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by brajkumar@chromium.org
, Mar 18 2016Labels: -Type-Bug M-51 OS-Android OS-Windows Type-Bug-Regression
Owner: sorin@chromium.org
Status: Assigned (was: Unconfirmed)