New issue
Advanced search Search tips

Issue 615534 link

Starred by 1 user

Issue metadata

Status: Untriaged
Owner: ----
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 1
Type: Bug



Sign in to add a comment

BN_generate_dsa_nonce

Project Member Reported by rookrishna@chromium.org, May 27 2016

Issue description

Chrome OS 53.0.2749.3/8377.0.0 samus

Report ID 730bcb9c00000000
Thread 11 CRASHED [SIGSEGV @ 0x00000000 ] MAGIC SIGNATURE THREAD
0x00007fb8c685faf4	(chrome -random.c:257 )	BN_generate_dsa_nonce
0x00007fb8c759b554	(chrome + 0x01ec6554 )	ff_put_no_rnd_mpeg4_qpel16_h_lowpass_mmxext
0x00007fb8c759b610	(chrome + 0x01ec6610 )	ff_put_mpeg4_qpel8_h_lowpass_mmxext
0x00007fb8c8e15757	(chrome -app_info_permissions_panel.cc:235 )	AppInfoPermissionsPanel::CreatePermissionsList
0x00007fb8c8e15820	(chrome -list.tcc:69 )	AppInfoPermissionsPanel::CreatePermissionsList
0x00007fb8c8e6e071	(chrome -stacked_tab_strip_layout.cc:191 )	StackedTabStripLayout::RemoveTab
0x00007fb8c8e6e400	(chrome -stl_vector.h:898 )	StackedTabStripLayout::IsStacked
0x00007fb8c8e1507a	(chrome -atomicity.h:68 )	AppInfoHeaderPanel::ShowAppInWebStore
0x00007fb8c641097c	(chrome -stl_deque.h:1430 )	std::deque<safe_browsing::LocalSafeBrowsingDatabaseManager::QueuedCheck, std::allocator<safe_browsing::LocalSafeBrowsingDatabaseManager::QueuedCheck> >::push_back
0x00007fb8c636dba5	(chrome + 0x00c98ba5 )	_init
0x00000002f8df9e76		
0x00007fb8c638c6a1	(chrome -chrome_access_token_store.cc:92 )	TokenLoadingJob::RespondOnOriginatingThread
0x00007fb8c636d8ae	(chrome + 0x00c988ae )	_init
0x00007fb8baedebbf		
0x00007fb8c6bfeab7	(chrome -printer_description.cc:354 )	cloud_devices::printer::Media::MatchBySize
0x00007fb8c6be8508	(chrome -url_canon.h:153 )	url::ResolveRelative
0x00007fb8c8e196e4	(chrome -string16.h:90 )	BookmarkBubbleView::ApplyEdits
0x00007fb8c8e19897	(chrome + 0x03744897 )	
0x00007fb8c6c12407	(chrome -crx_downloader.h:52 )	std::vector<update_client::CrxDownloader::DownloadMetrics, std::allocator<update_client::CrxDownloader::DownloadMetrics> >::operator=
0x00007fb8c6c10555	(chrome -stl_tree.h:481 )	component_updater::CrxUpdateService::CrxUpdateService
0x00007fb8c409d306	(libpthread-2.19.so -pthread_create.c:309 )	start_thread
 
Labels: Needs-Feedback
This stack trace looks like total garbage.

AppInfoPermissionsPanel::CreatePermissionsList has no reason to call into ffmpeg, which has no reason to call into BoringSSL. Whether StackedTabStripLayout has a reason to call into AppInfoPermissionPanel I have no idea. Having Safe Browsing call into that mess certainly doesn't make sense, though it could just be aggressive deduping by the linker. Also having a bunch of _inits on the stack is weird.

Then we have cloud_devices::printer::Media::MatchBySize calling into TokenLoadingJob::RespondOnOriginatingThread which can't happen since the latter is only called via PostTaskAndReply.

On top of that, url::ResolveRelative is calling into all of that??


How did you trigger this?
Labels: -Needs-Feedback
There is no extact repro steps but the whole browser crashed and there were bunch of crashes and this was one of them 
Which were the other crashes? This report really isn't actionable since the entire stack is pretty much garbage.
Crash ID 6716cb9c00000000 (Chrome)

Automatically reported Friday, May 27, 2016 at 2:40:44 PM

Provide additional details

Crash ID 75e1eb1a00000000 (Chrome)

Automatically reported Friday, May 27, 2016 at 2:40:41 PM

Provide additional details

Crash ID 270bcb9c00000000 (Chrome)

Automatically reported Friday, May 27, 2016 at 2:40:39 PM

Provide additional details

Crash ID bbe2cb9c00000000 (Chrome)

Automatically reported Friday, May 27, 2016 at 2:40:36 PM

Provide additional details

Crash ID 730bcb9c00000000 (Chrome)

Automatically reported Friday, May 27, 2016 at 2:40:34 PM

Provide additional details
All the other crashes leads to 

0x00007f5c39ddcb92	(chrome -web_ui_controller.h:39 )	chromeos::OobeUI::OobeUI
0x00007f5c39cc7378	(chrome -bitset:1046 )	blink::CSSPropertyMetadata::isEnabledProperty
0x00007f5c39cc793e	(chrome -StringImpl.h:291 )	blink::AnimationEffectTimingProperties::AnimationEffectTimingProperties
0x00007f5c39cc7eb5	(chrome -FontFaceDescriptors.cpp:19 )	blink::FontFaceDescriptors::FontFaceDescriptors
0x00007f5c39cc4ab6	(chrome -HashTable.h:592 )	blink::StyleBuilderFunctions::applyInitialCSSPropertyGridTemplateRows
0x00007f5c39de8568	(chrome -signin_screen_handler.cc:821 )	chromeos::SigninScreenHandler::HideOfflineMessage
0x00007f5c3b6cd112	(chrome -cffl_iformfiller.cpp:751 )	CFFL_IFormFiller::OnClick
0x00007f5c3b6cd3ab	(chrome + 0x04e413ab )	
0x00007f5c3b6ca66c	(chrome -stl_deque.h:196 )	std::deque<PAGECHAR_INFO, std::allocator<PAGECHAR_INFO> >::_M_erase
0x00007f5c3a9bb125	(chrome -custom_button.cc:107 )	<name omitted>
0x00007f5c3a9bcaa1	(chrome -unique_ptr.h:76 )	views::ImageButton::~ImageButton
0x00007f5c3a9bcf7c	(chrome -image_button.cc:193 )	views::ImageButton::ComputeImagePaintPosition
0x00007f5c3a9b6dfc	(chrome -rect.h:41 )	views::BubbleFrameView::GetPreferredSize
0x00007f5c37a52b9e	(chrome -deflate.c:201 )	MOZ_Z_deflateSetDictionary
Yeah, every one of those stack traces looks like garbage. I'm not sure what there is to be done. Probably the only hope is to find someone who works on the crash reporting tool to double-check that the symbolization didn't go crazy.
Components: -Internals>Network>SSL Internals>CrashReporting
Moving to CrashReporting for lack of a better component when "stack traces go bad". I don't know who owns that code who can look into it.
Project Member

Comment 8 by sheriffbot@chromium.org, Jul 8 2016

Labels: -M-53 M-54 MovedFrom-53
Moving this nonessential bug to the next milestone.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment