New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 622512 link

Starred by 3 users

Issue metadata

Status: Duplicate
Merged: issue 622098
Owner: ----
Closed: Jun 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 1
Type: Bug



Sign in to add a comment

Chrome crashes every time I navigate to gmail.com

Project Member Reported by erikc...@chromium.org, Jun 22 2016

Issue description

I restarted Chrome using the "restart now" button on about://chrome, and now it crashes shortly after startup.

excerpt from crash log:
OS|Mac OS X|10.11.5 15F34
Module|Google Chrome Framework|2776.0.0.0|Google Chrome Framework|74312B171CF43E52ACF42BC2E91DC8D60|0x10d462000|0x114246fff|0

Thread 19 ( * CRASHED * EXC_BAD_ACCESS / KERN_INVALID_ADDRESS @ 0x0 )
0	 [Google Chrome Framework	 -	 ssl_client_socket_impl.cc:1409] net::SSLClientSocketImpl::VerifyCT()
1	 [Google Chrome Framework	 -	 ssl_client_socket_impl.cc:1361] net::SSLClientSocketImpl::DoVerifyCertComplete(int)
2	 [Google Chrome Framework	 -	 ssl_client_socket_impl.cc:1509] net::SSLClientSocketImpl::DoHandshakeLoop(int)
3	 [Google Chrome Framework	 -	 ssl_client_socket_impl.cc:1442] net::SSLClientSocketImpl::OnHandshakeIOComplete(int)
4	 [Google Chrome Framework	 -	 ssl_client_socket_impl.cc:1465] net::SSLClientSocketImpl::OnRecvComplete(int)
5	 [Google Chrome Framework	 -	 scoped_tracker.h:39] net::TCPClientSocket::DidCompleteReadWrite(base::Callback<void (int), (base::internal::CopyMode)1> const&, int)
6	 [Google Chrome Framework	 -	 tcp_socket_posix.cc:589] net::TCPSocketPosix::ReadCompleted(scoped_refptr<net::IOBuffer> const&, base::Callback<void (int), (base::internal::CopyMode)1> const&, int)
7	 [Google Chrome Framework	 -	 callback_internal.h:108] net::SocketPosix::ReadCompleted()
8	 [Google Chrome Framework	 -	 trace_event.h:977] net::SocketPosix::OnFileCanReadWithoutBlocking(int)
9	 [Google Chrome Framework	 -	 message_pump_libevent.cc:95] base::MessagePumpLibevent::OnLibeventNotification(int, short, void*)
10	 [Google Chrome Framework	 -	 event.c:382] event_base_loop
11	 [Google Chrome Framework	 -	 message_pump_libevent.cc:222] base::MessagePumpLibevent::Run(base::MessagePump::Delegate*)
12	 [Google Chrome Framework	 -	 run_loop.cc:36] base::RunLoop::Run()
13	 [Google Chrome Framework	 -	 message_loop.cc:296] base::MessageLoop::Run()
14	 [Google Chrome Framework	 -	 browser_thread_impl.cc:224] content::BrowserThreadImpl::IOThreadRun(base::MessageLoop*)
15	 [Google Chrome Framework	 -	 browser_thread_impl.cc:259] content::BrowserThreadImpl::Run(base::MessageLoop*)
16	 [Google Chrome Framework	 -	 lock.h:26] base::Thread::ThreadMain()
17	 [Google Chrome Framework	 -	 platform_thread_posix.cc:72] base::(anonymous namespace)::ThreadFunc(void*)
18	 [libsystem_pthread.dylib	 -	 0x399d] _pthread_body
19	 [libsystem_pthread.dylib	 -	 0x391a] _pthread_body
20	 [libsystem_pthread.dylib	 -	 0x1351] thread_start
21	 [Google Chrome Framework	 -	 platform_thread_posix.cc:47] base::(anonymous namespace)::ThreadFunc(void*)

 
Labels: ReleaseBlock-Dev M-53
Attaching some traces.
temp2
30.3 KB View Download
temp3
40.5 KB View Download
Can you attach your chrome://version variations?

There's at least one crash if you enable the media router with Chromecast, as the bots didn't catch it - that's  Issue 622098 .
Issue 622539 has been merged into this issue.
I can't navigate to chrome://version. In the opening post, I included the framework version (2776), which corresponds to the release 53.0.2776.0.
I wanted the chrome://version output for the variations, to see if it correlates to a finch trial that isn't being tested on the waterfall.

I've got at least one crash report from Windows that I'm trying to debug, but it's something that doesn't exist on the waterfall that's triggering it.
I was crashing 100% of the time. As per https://groups.google.com/a/google.com/forum/#!msg/finch-users/3T9EOzb8Pvo/5GXRv5F6c0gJ, I added the flag --enable-benchmarking to set all Finch experiments to Default. No crash.

Relaunching without the flag, still no crash. Adding info from chrome://version


Google Inc.
Copyright 2016 Google Inc. All rights reserved.
Google Chrome	53.0.2776.0 (Official Build) canary (64-bit)
Revision	07025e9df358bb0249550d6124b9817333421fc0-refs/heads/master@{#401299}
OS	Mac OS X 
Blink	537.36 (@07025e9df358bb0249550d6124b9817333421fc0)
JavaScript	V8 5.3.298
Flash	22.0.0.196
User Agent	Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2776.0 Safari/537.36
Command Line	/Applications/Google Chrome Canary.app/Contents/MacOS/Google Chrome Canary --flag-switches-begin --enable-app-info-dialog-mac --enable-mac-views-native-app-windows --top-chrome-md=material --flag-switches-end
Executable Path	/Applications/Google Chrome Canary.app/Contents/MacOS/Google Chrome Canary
Profile Path	/Users/erikchen/Library/Application Support/Google/Chrome Canary/Profile 4
Variations	16e0dd70-3f4a17df
b3888d8d-459fc675
4a449931-f23d1dea
6345b824-3f4a17df
7c1bc906-f55a7974
1c752ce9-f23d1dea
ba3f87da-f23d1dea
f049a919-3f4a17df
76b48ab8-a2567007
31362330-3f4a17df
c70841c8-a2567007
290c251-3f4a17df
f15c1c09-ca7d8d80
4410ee9c-f23d1dea
9ffc5535-42aa1e47
dd4da2fc-3f4a17df
43d0dd1e-3f4a17df
bcc907f7-870290a7
2e109477-bcf405c8
6d340565-ca7d8d80
9e5c75f1-7491430a
6488ba84-f23d1dea
64cbdfc2-ca7d8d80
c3ad0f6b-ca7d8d80
f79cb77b-3f4a17df
b7786474-54f732d1
23a898eb-ca7d8d80
868bda90-f23d1dea
4ea303a6-99aa90df
d5b671a5-ca7d8d80
9736de91-3f4a17df
30e679f-ca7d8d80
ad6d27cc-3e870323
ca314179-ca7d8d80
69bf80fa-3f4a17df
867c4c68-3f4a17df
76923fa8-e0ae2f34
3ac60855-3ec2a267
f296190c-1facebc5
4442aae2-4ad60575
ed1d377-e1cc0f14
75f0f0a0-6bdfffe7
e2b18481-e1cc0f14
e7e71889-e1cc0f14
b39ea213-d1372334
fe05be5f-4001c964
61b920c1-f23d1dea
46567c16-3f4a17df
cd9fec2f-f23d1dea
828a5926-d8f52f32
Cc: shrike@chromium.org
+shrike, as this is a serious regression to Canary.

Comment 9 Deleted

Trying to keep this bug open (Not RVG) so deleted the one about crash details.

EnableMediaRouter is the cause of the crash, and that's because of  Issue 622098 

It's a 4 line fix, the issue is in testing. I haven't heard back from the media team on how to repro this, but I'll just put a blind patch in.

It does mean that there's *no waterfall coverage* for this feature. So It should probably be turned off on Finch.

Comment 11 Deleted

Mergedinto: 622098
Status: Duplicate (was: Untriaged)

Sign in to add a comment