New issue
Advanced search Search tips

Issue 648492 link

Starred by 3 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Oct 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: Android
Pri: 2
Type: Bug



Sign in to add a comment

Native crash caused by webview from Chrome.apk

Reported by fancla...@gmail.com, Sep 20 2016

Issue description

Steps to reproduce the problem:
1. Run stress test on HTCMail app
2. 
3. 

What is the expected behavior?
No native crash

What went wrong?
09-14 20:02:51.654 10502 10299 F google-breakpad: -----BEGIN BREAKPAD MICRODUMP-----
09-14 20:02:51.654 10502 10299 F google-breakpad: V WebView:52.0.2743.98
09-14 20:02:51.654 10502 10299 F google-breakpad: O A arm 04 armv8l htc/pmewl_00531/htc_pmewl:7.0/NRD90M/809116.1:user/release-keys
09-14 20:02:51.655 10502 10299 F google-breakpad: G OpenGL ES 3.2 V@145.0 (GIT@I282654f454)|Qualcomm|Adreno (TM) 530

09-14 20:02:51.778 10299 10299 I art : NativeCrashSigHandler RECEIVE SIGNAL: 11, PID: 10299, TID: 10299
09-14 20:02:51.778 10299 10299 I art : VMHOOK: rlim_cur : 4294967295 pid:10299
09-14 20:02:51.778 10299 10504 I art : Fault address: 0x720054 code:1 (SEGV_MAPERR)
09-14 20:02:51.779 10299 10504 I art : DumpForSigCrash, Crashed thread:
09-14 20:02:51.781 10299 10504 I art : "main" prio=7 tid=1 Native
09-14 20:02:51.781 10299 10504 I art : | group="" sCount=0 dsCount=0 obj=0x758cf850 self=0xf7203400
09-14 20:02:51.781 10299 10504 I art : | sysTid=10299 nice=-4 cgrp=default sched=0/0 handle=0xf72be534
09-14 20:02:51.781 10299 10504 I art : | state=S schedstat=( 5927877572 1169753629 5950 ) utm=413 stm=179 core=2 HZ=100
09-14 20:02:51.781 10299 10504 I art : | stack=0xff50a000-0xff50c000 stackSize=8MB
09-14 20:02:51.781 10299 10504 I art : | held mutexes= "mutator lock"(shared held)
09-14 20:02:51.781 10299 10504 I art : kernel: __switch_to+0x7c/0x88
09-14 20:02:51.782 10299 10504 I art : kernel: futex_wait_queue_me+0xe4/0x160
09-14 20:02:51.782 10299 10504 I art : kernel: futex_wait+0xf4/0x208
09-14 20:02:51.782 10299 10504 I art : kernel: do_futex+0xcc/0x874
09-14 20:02:51.782 10299 10504 I art : kernel: compat_SyS_futex+0xcc/0x144
09-14 20:02:51.782 10299 10504 I art : kernel: el0_svc_naked+0x24/0x28
09-14 20:02:51.782 10299 10504 I art : at org.chromium.android_webview.AwContents.nativeDestroy(Native method)
09-14 20:02:51.782 10299 10504 I art : at org.chromium.android_webview.AwContents.access$000(AwContents.java:98)
09-14 20:02:51.783 10299 10504 I art : at org.chromium.android_webview.AwContents$AwContentsDestroyRunnable.run(AwContents.java:371)
09-14 20:02:51.783 10299 10504 I art : at org.chromium.content.common.CleanupReference.runCleanupTaskInternal(CleanupReference.java:164)

09-14 20:02:51.951 10299 10299 F libc : Fatal signal 11 (SIGSEGV), code 1, fault addr 0x720054 in tid 10299 (tc.android.mail)
09-14 20:02:51.951 6101 6101 V Perf : com.cmcm.onews.service.LocalService@e77f639 onDestroy, 0ms
09-14 20:02:51.952 603 603 W : debuggerd: handling request: pid=10299 uid=10041 gid=10041 tid=10299
09-14 20:02:52.038 10506 10506 F DEBUG : *** *** *** *** *** *** *** *** *** *** *** *** *** *** *** ***
09-14 20:02:52.038 10506 10506 F DEBUG : Build fingerprint: 'htc/pmewl_00531/htc_pmewl:7.0/NRD90M/809116.1:user/release-keys'
09-14 20:02:52.039 10506 10506 F DEBUG : Revision: '0'
09-14 20:02:52.040 10506 10506 F DEBUG : ABI: 'arm'
09-14 20:02:52.041 10506 10506 F DEBUG : pid: 10299, tid: 10299, name: tc.android.mail >>> com.htc.android.mail <<<
09-14 20:02:52.041 10506 10506 F DEBUG : signal 11 (SIGSEGV), code 1 (SEGV_MAPERR), fault addr 0x720054
09-14 20:02:52.042 10506 10506 F DEBUG : r0 d4544080 r1 00720054 r2 00000000 r3 00000000
09-14 20:02:52.042 10506 10506 F DEBUG : r4 00720054 r5 d4544080 r6 00000000 r7 00000000
09-14 20:02:52.043 10506 10506 F DEBUG : r8 00000005 r9 00000004 sl d1ec1690 fp 00000004
09-14 20:02:52.043 10506 10506 F DEBUG : ip 00000000 sp ffd05160 lr df136dd9 pc df136dd2 cpsr 600f0030
09-14 20:02:52.046 10506 10506 F DEBUG : 
09-14 20:02:52.046 10506 10506 F DEBUG : backtrace:
09-14 20:02:52.047 10506 10506 F DEBUG : #00 pc 00d6add2 /system/app/Chrome/Chrome.apk (offset 0x4632000)

************************************************************************
*                             Native Crash                             *
************************************************************************
com.htc.android.mail : 1 time

com.htc.android.mail
events_e0020_0001_20160914_205109_HT61DBN00006_htc_pmewl_2.07.531.1.txt
09-14 20:52:01.542  1591  4249 I am_crash: [1591,0,com.htc.android.mail,948682309,Native crash,Aborted,unknown,0]

device_e0020_0001_20160914_205108_HT61DBN00006_htc_pmewl_2.07.531.1.txt
09-14 20:52:00.055  4243  4243 F DEBUG   : Build fingerprint: 'htc/pmewl_00531/htc_pmewl:7.0/NRD90M/809116.1:user/release-keys'
09-14 20:52:00.056  4243  4243 F DEBUG   : Revision: '0'
09-14 20:52:00.056  4243  4243 F DEBUG   : ABI: 'arm'
09-14 20:52:00.056  4243  4243 F DEBUG   : pid: 3786, tid: 3985, name: Compositor  >>> com.htc.android.mail <<<
09-14 20:52:00.056  4243  4243 F DEBUG   : signal 6 (SIGABRT), code -6 (SI_TKILL), fault addr --------
09-14 20:52:00.057  4243  4243 F DEBUG   :     r0 00000000  r1 00000f91  r2 00000006  r3 00000008
09-14 20:52:00.057  4243  4243 F DEBUG   :     r4 d20ff978  r5 00000006  r6 d20ff920  r7 0000010c
09-14 20:52:00.057  4243  4243 F DEBUG   :     r8 d77454c4  r9 d7736138  sl d20ff338  fp d7736120
09-14 20:52:00.057  4243  4243 F DEBUG   :     ip 00000000  sp d20ff2a8  lr f6bc0bb7  pc f6bc3438  cpsr 20030010
09-14 20:52:00.061  4243  4243 F DEBUG   : 
09-14 20:52:00.061  4243  4243 F DEBUG   : backtrace:
09-14 20:52:00.061  4243  4243 F DEBUG   :     #00 pc 0004a438  /system/lib/libc.so (tgkill+12)
09-14 20:52:00.061  4243  4243 F DEBUG   :     #01 pc 00047bb3  /system/lib/libc.so (pthread_kill+34)
09-14 20:52:00.061  4243  4243 F DEBUG   :     #02 pc 0001d7f9  /system/lib/libc.so (raise+10)
09-14 20:52:00.062  4243  4243 F DEBUG   :     #03 pc 000192f1  /system/lib/libc.so (__libc_android_abort+34)
09-14 20:52:00.062  4243  4243 F DEBUG   :     #04 pc 00017358  /system/lib/libc.so (abort+4)
09-14 20:52:00.062  4243  4243 F DEBUG   :     #05 pc 01eb77bd  /system/app/Chrome/Chrome.apk (offset 0x4632000)

Call stack:
#00 pc 0004a438  /system/lib/libc.so (tgkill+12)
#01 pc 00047bb3  /system/lib/libc.so (pthread_kill+34)
#02 pc 0001d7f9  /system/lib/libc.so (raise+10)
#03 pc 000192f1  /system/lib/libc.so (__libc_android_abort+34)
#04 pc 00017358  /system/lib/libc.so (abort+4)
#05 pc 01eb77bd  /system/app/Chrome/Chrome.apk (offset 0x4632000)

Crashed report ID: 

How much crashed? Whole browser

Is it a problem with a plugin? N/A 

Did this work before? N/A 

Chrome version: 52.0.2743.98  Channel: n/a
OS Version: 7.0
Flash Version: 

Happen on many devices
 
Components: Mobile>WebView

Comment 2 by torne@chromium.org, Sep 21 2016

You need to include the full log, including the breakpad microdump (all the hexdump-style output) that you omitted, otherwise we can't tell why it crashed.

Comment 3 by fancla...@gmail.com, Sep 22 2016

Upload full log of native crash.
We give native crash logs from two different devices, please kindly help this issue, thanks.
NativeCrashLog.zip
26.0 MB Download

Comment 4 by fancla...@gmail.com, Sep 22 2016

Upload another two native crash logs from other devices.
Native crash happen on webview from "/data/app/com.android.chrome-1/base.apk".

NativeCrashLog_2.zip
28.2 MB Download

Comment 5 by torne@chromium.org, Sep 22 2016

Operating system: Android
                  htc/pmewl_00531/htc_pmewl:7.0/NRD90M/809116.1:user/release-keys
CPU: arm
     4 CPUs

GPU: OpenGL ES 3.2 V@145.0 (GIT@I282654f454)
     Qualcomm
     Adreno (TM) 530

Crash reason:  
Crash address: 0x0
Process uptime: not available

Thread 0 (crashed)
 0  libmonochrome.so!GLImageSync::~GLImageSync [texture_definition.cc : 76 + 0x2]
     r0 = 0xcd622528    r1 = 0xd80cabb0    r2 = 0xe0ac6db8    r3 = 0x00720054
     r4 = 0xd80cabb0    r5 = 0xd0862c00    r6 = 0xcf01ac50    r7 = 0xcf222680
     r8 = 0xd7519580    r9 = 0x00000001   r10 = 0x0000018d   r12 = 0xe0bbeca0
     fp = 0x0000018c    sp = 0xd15bf0a8    lr = 0xdee1cbf5    pc = 0xdee1cbc8
    Found by: given as instruction pointer in context
 1  libmonochrome.so!GLImageSync::~GLImageSync [texture_definition.cc : 77 + 0x3]
     r3 = 0xdee1cbed    r4 = 0xd80cabb0    r5 = 0xd0862c00    r6 = 0xcf01ac50
     r7 = 0xcf222680    r8 = 0xd7519580    r9 = 0x00000001   r10 = 0x0000018d
     fp = 0x0000018c    sp = 0xd15bf0b8    pc = 0xdee1cbf5
    Found by: call frame info
 2  libmonochrome.so!gpu::gles2::Texture::LevelInfo::~LevelInfo [ref_counted.h : 137 + 0x5]
     r4 = 0xd0862c00    r5 = 0xd0862c00    r6 = 0xcf01ac50    r7 = 0xcf222680
     r8 = 0xd7519580    r9 = 0x00000001   r10 = 0x0000018d    fp = 0x0000018c
     sp = 0xd15bf0c0    pc = 0xde80dde3
    Found by: call frame info
 3  libmonochrome.so!gpu::gles2::Texture::FaceInfo::~FaceInfo [memory : 1700 + 0x3]
     r4 = 0xd11df5c0    r5 = 0xd0862c00    r6 = 0xcf01ac50    r7 = 0xcf222680
     r8 = 0xd7519580    r9 = 0x00000001   r10 = 0x0000018d    fp = 0x0000018c
     sp = 0xd15bf0c8    pc = 0xde80ddaf
    Found by: call frame info
 4  libmonochrome.so!gpu::gles2::Texture::~Texture [memory : 1700 + 0x3]
     r3 = 0x00000010    r4 = 0xcf222680    r5 = 0xd11df5c0    r6 = 0xcf01ac50
     r7 = 0xcf222680    r8 = 0xd7519580    r9 = 0x00000001   r10 = 0x0000018d
     fp = 0x0000018c    sp = 0xd15bf0d8    pc = 0xde80dcd9
    Found by: call frame info
 5  libmonochrome.so!gpu::gles2::Texture::RemoveTextureRef [texture_manager.cc : 409 + 0x5]
     r4 = 0xcf01bdd8    r5 = 0xcf01bdd8    r6 = 0xcf01ac50    r7 = 0xcf222680
     r8 = 0xd7519580    r9 = 0x00000001   r10 = 0x0000018d    fp = 0x0000018c
     sp = 0xd15bf0e8    pc = 0xde80dc1f
    Found by: call frame info
 6  libmonochrome.so!gpu::gles2::TextureRef::~TextureRef [texture_manager.cc : 1710 + 0xd]
     r4 = 0xcf01ac50    r5 = 0xcf01ac50    r6 = 0xf7066da0    r7 = 0x00000039
     r8 = 0xd7519580    r9 = 0xd7519580   r10 = 0x0000018d    fp = 0x0000018c
     sp = 0xd15bf100    pc = 0xde80db0f
    Found by: call frame info
 7  libmonochrome.so!gpu::gles2::TextureManager::RemoveTexture [ref_counted.h : 137 + 0x5]
     r4 = 0xd7519610    r5 = 0xcf01ac50    r6 = 0xf7066da0    r7 = 0x00000039
     r8 = 0xd7519580    r9 = 0xd7519580   r10 = 0x0000018d    fp = 0x0000018c
     sp = 0xd15bf108    pc = 0xde80daed
    Found by: call frame info
 8  libmonochrome.so!gpu::gles2::GLES2DecoderImpl::DeleteTexturesHelper [gles2_cmd_decoder.cc : 830 + 0x7]
     r4 = 0xcf01ac50    r5 = 0xd1832900    r6 = 0xd7751098    r7 = 0x00000000
     r8 = 0x00000001    r9 = 0x00000000   r10 = 0xd1832974    fp = 0x0000002d
     sp = 0xd15bf168    pc = 0xde80d66d
    Found by: call frame info
 9  libmonochrome.so!gpu::gles2::GLES2DecoderImpl::HandleDeleteTexturesImmediate [gles2_cmd_decoder_autogen.h : 975 + 0x5]
     r4 = 0x00000004    r5 = 0x00000000    r6 = 0x00000134    r7 = 0xd7751090
     r8 = 0x00000024    r9 = 0xd1832900   r10 = 0x00000027    fp = 0x0000002d
     sp = 0xd15bf188    pc = 0xde80d61b
    Found by: call frame info
10  libmonochrome.so!gpu::gles2::GLES2DecoderImpl::DoCommandsImpl<false> [gles2_cmd_decoder.cc : 4606 + 0x3]
     r3 = 0xde80d5f1    r4 = 0x00000003    r5 = 0x00000068    r6 = 0x00000134
     r7 = 0xd7751090    r8 = 0x00000024    r9 = 0xd1832900   r10 = 0x00000027
     fp = 0x0000002d    sp = 0xd15bf198    pc = 0xde7e49f9
    Found by: call frame info
11  libmonochrome.so!gpu::CommandParser::ProcessCommands [cmd_parser.cc : 54 + 0x9]
     r4 = 0xcf0193f0    r5 = 0xde7e48e5    r6 = 0x00000000    r7 = 0xd7751000
     r8 = 0xf4c65008    r9 = 0xd15bf2d0   r10 = 0xd15bf45c    fp = 0xd15bf3d0
     sp = 0xd15bf270    pc = 0xde7e48cf
    Found by: call frame info
12  libmonochrome.so!gpu::CommandExecutor::PutChanged [command_executor.cc : 61 + 0x7]
     r4 = 0xd223e020    r5 = 0xcf0193f0    r6 = 0x9e41bc62    r7 = 0x00000034
     r8 = 0xf4c65008    r9 = 0xd15bf2d0   r10 = 0xd15bf45c    fp = 0xd15bf3d0
     sp = 0xd15bf298    pc = 0xdedeae89
    Found by: call frame info
13  libmonochrome.so!base::internal::Invoker<base::IndexSequence<0u>, base::internal::BindState<base::internal::RunnableAdapter<void (IOThread::*)()>, void(IOThread*), base::internal::UnretainedWrapper<IOThread> >, base::internal::InvokeHelper<false, void, base::internal::RunnableAdapter<void (IOThread::*)()> >, void()>::Run [bind_internal.h : 311 + 0x7]
     r4 = 0xd6b45500    r5 = 0xe0be61d4    r6 = 0xe0c7d528    r7 = 0xd15bf3e4
     r8 = 0x00000000    r9 = 0x0000002d   r10 = 0xd15bf45c    fp = 0xd15bf3d0
     sp = 0xd15bf350    pc = 0xdeae3d73
    Found by: call frame info
14  libmonochrome.so!gpu::GpuCommandBufferStub::OnAsyncFlush [gpu_command_buffer_stub.cc : 770 + 0x3]
     r4 = 0xd6b45500    r5 = 0xe0be61d4    r6 = 0xe0c7d528    r7 = 0xd15bf3e4
     r8 = 0x00000000    r9 = 0x0000002d   r10 = 0xd15bf45c    fp = 0xd15bf3d0
     sp = 0xd15bf360    pc = 0xdef63839
    Found by: call frame info
15  libmonochrome.so!IPC::MessageT<GpuCommandBufferMsg_AsyncFlush_Meta, std::__1::tuple<int, unsigned int, std::__1::vector<ui::LatencyInfo, std::__1::allocator<ui::LatencyInfo> > >, void>::Dispatch<gpu::GpuCommandBufferStub, gpu::GpuCommandBufferStub, void, void (gpu::GpuCommandBufferStub::*)(int, unsigned int, const std::__1::vector<ui::LatencyInfo>&)> [tuple.h : 166 + 0x7]
     r4 = 0xdef63741    r5 = 0x00000001    r6 = 0xd6b45500    r7 = 0x00000001
     r8 = 0xd09cab20    r9 = 0xf4c65008   r10 = 0xededee12    fp = 0xe06a6628
     sp = 0xd15bf420    pc = 0xdef63a0d
    Found by: call frame info
16  libmonochrome.so!gpu::GpuCommandBufferStub::OnMessageReceived [gpu_command_buffer_stub.cc : 241 + 0x11]
     r4 = 0xd09cab20    r5 = 0xd6b45500    r6 = 0xd15bf570    r7 = 0x00000001
     r8 = 0xd15bf588    r9 = 0xf4c65008   r10 = 0xededee12    fp = 0xe06a6628
     sp = 0xd15bf480    pc = 0xdef64603
    Found by: call frame info
17  libmonochrome.so!gpu::GpuChannel::HandleMessageHelper [gpu_channel.cc : 810 + 0x5]
     r4 = 0xd6b45b00    r5 = 0xd09cab20    r6 = 0xd6b45500    r7 = 0xd6b45b00
     r8 = 0xd30c63c0    r9 = 0x00000000   r10 = 0xededee12    fp = 0xe06a6628
     sp = 0xd15bf630    pc = 0xdef6252d
    Found by: call frame info
18  libmonochrome.so!gpu::GpuChannel::HandleMessage [gpu_channel.cc : 792 + 0x7]
     r4 = 0xd09ea878    r5 = 0xd09cab20    r6 = 0xd6b45500    r7 = 0xd6b45b00
     r8 = 0xd30c63c0    r9 = 0x00000000   r10 = 0xededee12    fp = 0xe06a6628
     sp = 0xd15bf640    pc = 0xdef62591
    Found by: call frame info
19  libmonochrome.so!base::internal::Invoker<base::IndexSequence<0u, 1u>, base::internal::BindState<base::internal::RunnableAdapter<bool (IPC::Listener::*)(const IPC::Message&)>, void(IPC::Listener*, const IPC::Message&), const base::WeakPtr<IPC::Listener>&, const IPC::Message&>, base::internal::InvokeHelper<true, void, base::internal::RunnableAdapter<bool (IPC::Listener::*)(const IPC::Message&)> >, void()>::Run [bind_internal.h : 186 + 0x3]
     r4 = 0xd09ea868    r5 = 0xd15bf660    r6 = 0xd09ea878    r7 = 0xe0c7d4fa
     r8 = 0xd30c63c0    r9 = 0x00000000   r10 = 0xededee12    fp = 0xe06a6628
     sp = 0xd15bf660    pc = 0xdeae114f
    Found by: call frame info
20  libmonochrome.so!base::debug::TaskAnnotator::RunTask [callback.h : 397 + 0x5]
     r4 = 0xd15bf808    r5 = 0xd15bf6f0    r6 = 0xd15bf6e8    r7 = 0xe0c7d4fa
     r8 = 0xd30c63c0    r9 = 0x00000000   r10 = 0xededee12    fp = 0xe06a6628
     sp = 0xd15bf680    pc = 0xde71304f
    Found by: call frame info
21  libmonochrome.so!base::MessageLoop::RunTask [message_loop.cc : 478 + 0xd]
     r4 = 0xd15bf808    r5 = 0xd30c6300    r6 = 0xe0c7d4f0    r7 = 0xe0c7d470
     r8 = 0xe04bc306    r9 = 0xd15bf810   r10 = 0xededee12    fp = 0x0000006d
     sp = 0xd15bf740    pc = 0xde712e51
    Found by: call frame info
22  libmonochrome.so!base::MessageLoop::DeferOrRunPendingTask [message_loop.cc : 487 + 0x7]
     r4 = 0xd30c6300    r5 = 0x00000001    r6 = 0xd15bf808    r7 = 0xd30c630c
     r8 = 0xd15bf818    r9 = 0xd15bf810   r10 = 0xededee12    fp = 0x0000006d
     sp = 0xd15bf7e8    pc = 0xde712dd7
    Found by: call frame info
23  libmonochrome.so!base::MessageLoop::DoWork [message_loop.cc : 604 + 0x3]
     r3 = 0x00000000    r4 = 0xd30c6300    r5 = 0xd15bf808    r6 = 0xc0c0c0c1
     r7 = 0xd30c630c    r8 = 0xd15bf818    r9 = 0xd15bf810   r10 = 0xededee12
     fp = 0x0000006d    sp = 0xd15bf808    pc = 0xde712c7d
    Found by: call frame info
24  libmonochrome.so!base::MessagePumpDefault::Run [message_pump_default.cc : 33 + 0x7]
     r4 = 0x00000000    r5 = 0xd30c6300    r6 = 0x9dfbe570    r7 = 0x00000034
     r8 = 0xd6b42db8    r9 = 0xd6b42dc8   r10 = 0xde70ef69    fp = 0x00000000
     sp = 0xd15bf860    pc = 0xde712b6f
    Found by: call frame info
25  libmonochrome.so!base::RunLoop::Run [run_loop.cc : 35 + 0x5]
     r4 = 0xd15bf8b8    r5 = 0xd15bf894    r6 = 0xe67e3808    r7 = 0xd30c6300
     r8 = 0xd2b73da4    r9 = 0xd7d9def0   r10 = 0xde70ef69    fp = 0x00000000
     sp = 0xd15bf890    pc = 0xde712a3d
    Found by: call frame info
26  libmonochrome.so!base::MessageLoop::Run [message_loop.cc : 294 + 0x5]
     r4 = 0xe67e3800    r5 = 0xf4c65008    r6 = 0xe67e3808    r7 = 0xd30c6300
     r8 = 0xd2b73da4    r9 = 0xd7d9def0   r10 = 0xde70ef69    fp = 0x00000000
     sp = 0xd15bf8b8    pc = 0xde7129e9
    Found by: call frame info
27  libmonochrome.so!base::Thread::ThreadMain [thread.cc : 202 + 0x3]
     r4 = 0xe67e3800    r5 = 0xf4c65008    r6 = 0xe67e3808    r7 = 0xd30c6300
     r8 = 0xd2b73da4    r9 = 0xd7d9def0   r10 = 0xde70ef69    fp = 0x00000000
     sp = 0xd15bf8d8    pc = 0xde70f101
    Found by: call frame info
28  libmonochrome.so!ThreadFunc [platform_thread_posix.cc : 70 + 0x7]
     r4 = 0xd15bf920    r5 = 0xe67e3800    r6 = 0xd7bfa310    r7 = 0x00000078
     r8 = 0xd2b73da4    r9 = 0xd7d9def0   r10 = 0xde70ef69    fp = 0x00000000
     sp = 0xd15bf900    pc = 0xde70ef9d
    Found by: call frame info
29  libc.so + 0x47683
     r4 = 0xd15bf920    r5 = 0xf4c1f66d    r6 = 0xd15bf920    r7 = 0x00000078
     r8 = 0xd2b73da4    r9 = 0xd7d9def0   r10 = 0xde70ef69    fp = 0x00000000
     sp = 0xd15bf910    pc = 0xf4c1f685
    Found by: call frame info
30  libc.so + 0x19d69
     sp = 0xd15bf918    pc = 0xf4bf1d6b
    Found by: stack scanning
31  libmonochrome.so!base::ListValue::Equals(base::Value const*) const + 0x4e
     sp = 0xd15bf954    pc = 0xde70ef69
    Found by: stack scanning

Comment 6 by torne@chromium.org, Sep 22 2016

Of the first two logs you attached, one of them has the crash in #5 which is a completely different thing to the original report, and the another one has a segfault with no microdump at all. In the second two logs, they both crash in cc::AnimationTimeline::ClearPlayers, which is a different problem to the original report *and* #5. :(

So there's several different issues here, which may or may not be related. Can you provide a specific repro for any of these problems?

Comment 7 by torne@chromium.org, Sep 22 2016

Also, have you tried the new M53 release currently rolling out to stable, or M54 currently in beta?
Labels: Needs-Feedback

Comment 9 by fancla...@gmail.com, Sep 25 2016

For the latest two logs, the webview version is 53.0.2785.97.
And we will try to update M54 beta version to check this native crash problem.
Project Member

Comment 10 by sheriffbot@chromium.org, Oct 3 2016

Labels: -Needs-Feedback Needs-Review
Owner: timvolod...@chromium.org
Thank you for providing more feedback. Adding requester "timvolodine@chromium.org" for another review and adding "Needs-Review" label for tracking.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Owner: ----
have limited cycles right now, looks like a graphics issue though, maybe webview bugcop can have further look..

Comment 12 by boliu@chromium.org, Oct 11 2016

Labels: -Needs-Review Needs-Feedback
Is m54 beta ok then?
For our company policy, we can't test m54 beta in SST test.
Maybe we can test m54 stable by auto update from GP in next SST test, thanks.
Project Member

Comment 14 by sheriffbot@chromium.org, Oct 24 2016

Labels: -Needs-Feedback Needs-Review
Owner: boliu@chromium.org
Thank you for providing more feedback. Adding requester "boliu@chromium.org" for another review and adding "Needs-Review" label for tracking.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 15 by boliu@chromium.org, Oct 24 2016

Owner: ----
Status: WontFix (was: Unconfirmed)
if there is no repro, and you are not willing to test builds and whatnot, then we can't do much here

Sign in to add a comment