Repeated renderer crashes on v8::internal::ObjectStatsCollector when using --track_gc_object_stats/--noincremental-marking |
||||
Issue descriptionChrome Version : 55.0.2880.4 OS Version: OS X 10.11.6 URLs (if applicable) : https://store.google.com/product/asus_chromebook_flip Crash report: crash/0061581d00000000 Repro: 1. Start canary on mac passing --js-flags="--track_gc_object_stats --noincremental-marking" 2. Visit the URL above 3. scroll a bit up and down After few seconds chrome crashes with the stack trace in crash/0061581d00000000 Doesn't seem to repro without the js-flags cmdline.
,
Oct 5 2016
,
Oct 5 2016
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/4eaccc7a45662538c713001aa23f932228afefc8 commit 4eaccc7a45662538c713001aa23f932228afefc8 Author: mlippautz <mlippautz@chromium.org> Date: Wed Oct 05 10:23:51 2016 [heap] ObjectStats: Handle empty deoptimization input data BUG= chromium:652955 Review-Url: https://codereview.chromium.org/2393153002 Cr-Commit-Position: refs/heads/master@{#39984} [modify] https://crrev.com/4eaccc7a45662538c713001aa23f932228afefc8/src/heap/object-stats.cc
,
Oct 28 2016
Should be fixed. If you find other issues, please let me know.
,
Oct 28 2016
|
||||
►
Sign in to add a comment |
||||
Comment 1 by mlippautz@chromium.org
, Oct 5 2016Owner: mlippautz@chromium.org
Status: Assigned (was: Unconfirmed)