New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 613091 link

Starred by 5 users

Issue metadata

Status: Assigned
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Regression



Sign in to add a comment

Tab crash is seen after reloading the page in "metro.co.in"

Reported by adha...@etouch.net, May 19 2016

Issue description

Chrome Version:52.0.2741.0 (Official Build)19d105a2a1ec66924ff415f27ff170db7a67ba36-refs/heads/master@{#394609}(32/64-bit)
OS:Windows 8(Win 8-Aero enable)

URL:https://www.metro.co.in/

What steps will reproduce the problem?
(1)Launch chrome and navigate to the above url.
(2)Open dev tools and resize it 2-3 times.
(3)Reload the page and observe.

Actual: Tab crash is seen after reloading the page.

Expected: Tab crash should not be seen.

Crash ID c8b6006a00000000 (9b8641b8-a7cc-41d5-aca5-5385590d926c)

This is a Regression issue broken in M-50,below is the narrow bisect info:
https://chromium.googlesource.com/chromium/src/+log/d67ccdf83fa7606ec6bd028aa950ee91e00b395e..89f367a96adde631136877a0fe218e42493177e5?pretty=fuller&n=100

Suspecting:r373777?

Good build:50.0.2641.0
Bad build:50.0.2643.0

Kindly help to re-assign if your change is not the cause for this issue.

Note:Issue is not reproducible on Mac and Linux.
 
Actual crash.mp4
1.9 MB Download
Expected.mp4
1.9 MB Download
Labels: ReleaseBlock-Stable
Marking the above issue as RB-Stable as this is a recent regression.

Thank you!

Comment 2 by yosin@chromium.org, May 23 2016

Owner: ----
Status: Untriaged (was: Assigned)
r373777 doesn't relate this crash.
Cc: rnimmagadda@chromium.org
Just to update.

Able to repro this issue on Windows 7 for Google Chrome Canary Version - 53.0.2750.0 

Screen-recording is attached.
613091.mp4
1.4 MB Download
@adharap: Could you please look into this issue as per the comment #2
Labels: Needs-Feedback
Labels: -Needs-Feedback
Owner: dgozman@chromium.org
Status: Assigned (was: Untriaged)
Issue still(crash Id : 7326305a00000000 reproduced on canary 53.0.2753.0.

Stack trace:
-------------
Thread 0 CRASHED [EXCEPTION_STACK_OVERFLOW @ 0x000007feda740f94 ] MAGIC SIGNATURE THREAD
0x000007feda740f94	(chrome_child.dll -isolate.cc:360 )	v8::internal::Isolate::CaptureSimpleStackTrace(v8::internal::Handle<v8::internal::JSReceiver>,v8::internal::Handle<v8::internal::Object>)
0x000007feda741938	(chrome_child.dll -isolate.cc:474 )	v8::internal::Isolate::CaptureAndSetSimpleStackTrace(v8::internal::Handle<v8::internal::JSReceiver>,v8::internal::Handle<v8::internal::Object>)
0x000007feda74359e	(chrome_child.dll -isolate.cc:931 )	v8::internal::Isolate::StackOverflow()
0x000000d6911063ca		
0x000007fedaa4864f	(chrome_child.dll + 0x0115864f )	

From code search on the crashes file suspecting the below.
Suspect : https://codereview.chromium.org/1741893003
dgozman@ : Could you please take a look into this if its related to your change.

Cc: yangguo@chromium.org
Able to reproduce the crash on win8.1 latest canary #53.0.2760.0

ccing dev whose change may be related to this crash.
Labels: -hasbisect -ReleaseBlock-Stable Needs-Bisect
As per #7 , this issue is still manually reproducible, adharap@ could you please confirm and we need a re-bisect too.

Don't think the patch mentioned in #6 is the right suspect.

I can't reproduce this on Linux. I suspect though that it might be related to running out of stack space.

The default stack size for windows seems to be 984kB. If you can reproduce this reliably, can you test whether it still reproduces if you run chrome with --js-flags="--stack-size=900"?
Cc: pfeldman@chromium.org
Labels: -Needs-Bisect
====================================

Good Build:

48.0.2556.0    Base Position: 358220


Bad Build:

48.0.2557.0    Base Position: 358475

=====================================

Able to repro this issue on Windows 7 for the Google Chrome Stable Version - 51.0.2704.84

This is a regression issue broken in M48, below mentioned is the bisect info:

CHANGELOG URL: https://chromium.googlesource.com/chromium/src/+log/22f9fa2f7ba87632cdc5cfbfea2ce25fad2b0c83..d7dea63fb209a6a0379eadbd0682b88ceaf9a67c

Suspecting Commit: ff2c226ca3987bd30241845a4292da693214290d	

Review URL: https://codereview.chromium.org/1419093004

@dgozman: Could you please look into the issue, and if it has nothing to do with your changes and if possible please do assign it to the concerned owner.

Thank you.
Project Member

Comment 11 by sheriffbot@chromium.org, Jun 7 2016

Labels: -M-52 M-53 MovedFrom-52
Moving this nonessential bug to the next milestone.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Cc: -yangguo@chromium.org dgozman@chromium.org
Owner: yangguo@chromium.org
If the bisect is correct, I'm pretty sure it's v8 roll https://chromium.googlesource.com/chromium/src/+/059b808ec2c8a0a1be0fb53f71b93b9f60f90957.

But anyway this looks like a stack overflow crash. Not sure we can do something (similar to out-of-memory in v8). Yang, could you please route to someone from v8 team?
Cc: adamk@chromium.org
Adam, could this be related to shipping of @@toStringTag somehow?

https://chromium.googlesource.com/v8/v8/+/2fa4732739907bd8e52a421a5243184cd4e765d3

Comment 14 by adamk@chromium.org, Jun 15 2016

Cc: kozyatinskiy@chromium.org
Except for the bisect, this sounds to me like  issue 615485 .

I'm confused by the bisect info: the changelog doesn't even mention dgozman's ff2c226ca3987bd30241845a4292da693214290d. Are we sure this bisect is correct?

I wonder if reducing the stack size artificially causes this to bisect incorrectly.
Project Member

Comment 15 by sheriffbot@chromium.org, Jul 9 2016

Labels: -M-53 -Pri-1 M-54 MovedFrom-53 Pri-2
This issue is Pri-1 but has already been moved once. Lowering the priority and moving to the next milestone.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Cc: -ashej...@chromium.org

Sign in to add a comment