New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 655645 link

Starred by 3 users

Issue metadata

Status: Duplicate
Merged: issue 659026
Owner:
Closed: Oct 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug-Regression



Sign in to add a comment

Chrome: Crash Report - sandbox::SharedMemIPCServer::ThreadPingEventReady

Project Member Reported by tkonch...@chromium.org, Oct 13 2016

Issue description

Product name: Chrome
Magic Signature: sandbox::SharedMemIPCServer::ThreadPingEventReady

Current link:
https://crash.corp.google.com/browse?q=product.name%3D'Chrome'%20AND%20product.version%3D'54.0.2840.59'%20AND%20custom_data.ChromeCrashProto.ptype%3D'browser'%20AND%20ReportID%3D'05bbde5b00000000'%20AND%20custom_data.ChromeCrashProto.magic_signature_1.name%3D'sandbox%3A%3ASharedMemIPCServer%3A%3AThreadPingEventReady'&ignore_case=false&enable_rewrite=true&omit_field_name=&omit_field_value=&omit_field_opt=%3D#3


Search properties:
product.name: Chrome
product.version: 54.0.2840.59
custom_data.chromecrashproto.ptype: browser
reportid: 05bbde5b00000000

Metadata :
Product Name: Chrome
Product Version: 54.0.2840.59
Report ID: 05bbde5b00000000
Report Time: Thu, 13 Oct 2016 13:57:50 GMT
Uptime: 1000 ms
Cumulative Uptime: 0 ms
User Email: 
OS Name: Windows NT
OS Version: 6.1.7601 17514
CPU Architecture: x86
CPU Info: GenuineIntel family 6 model 63 stepping 2

Stack Trace:
Thread 6 CRASHED [EXCEPTION_ACCESS_VIOLATION_EXEC @ 0x00000800 ] MAGIC SIGNATURE THREAD
0x00000800		
0x01433dba	(chrome.exe -sharedmem_ipc_server.cc:395 )	sandbox::SharedMemIPCServer::ThreadPingEventReady(void *,unsigned char)
0x772e0b65	(ntdll.dll + 0x00070b65 )	RtlpTpWaitCallback
0x772b5a3c	(ntdll.dll + 0x00045a3c )	TppWaitpExecuteCallback
0x772b54f3	(ntdll.dll + 0x000454f3 )	TppCallbackCheckThreadBeforeCallback
0x765b33c9	(kernel32.dll + 0x000133c9 )	BaseThreadInitThunk
0x772a9ed1	(ntdll.dll + 0x00039ed1 )	__RtlUserThreadStart
0x772a9ea4	(ntdll.dll + 0x00039ea4 )	_RtlUserThreadStart

This crash exist since M49 build to latest dev

55.0.2883.9	0.20%	1	Dev
54.0.2840.59	16.16%	79	Beta/Stable

Link to the builds:
https://crash.corp.google.com/browse?q=product.name%3D%27Chrome%27%20AND%20custom_data.ChromeCrashProto.ptype%3D%27browser%27%20AND%20custom_data.ChromeCrashProto.magic_signature_1.name%3D%27sandbox%3A%3ASharedMemIPCServer%3A%3AThreadPingEventReady%27&ignore_case=false&enable_rewrite=true&omit_field_name=&omit_field_value=&omit_field_opt=%3D#samplereports:5,productversion:1000

Possible suspect : https://codereview.chromium.org/1231673002

Please reassign if this is not related to your change


 
Project Member

Comment 1 by sheriffbot@chromium.org, Oct 13 2016

Labels: Fracas FoundIn-M-54
Users experienced this crash on the following builds:

Win Beta 54.0.2840.59 -  5.15 CPM, 219 reports, 214 clients (signature sandbox::SharedMemIPCServer::ThreadPingEventReady)

If this update was incorrect, please add "Fracas-Wrong" label to prevent future updates.

- Go/Fracas
Cc: -cpu@chromium.org ligim...@chromium.org
Labels: Stability-Sheriff-Desktop M-54
This is listed as #2 browser crash in latest Stable reports - 54.0.2840.59 ,79.75% with 1500+ unique clients.

Almost all the reports have malware loaded - icaendpoint.dll,looping would to Stability sheriff for confirmation.

Details  below.
==============
https://crash.corp.google.com/browse?q=product.name%3D%27Chrome%27%20AND%20custom_data.ChromeCrashProto.ptype%3D%27browser%27%20AND%20custom_data.ChromeCrashProto.magic_signature_1.name%3D%27sandbox%3A%3ASharedMemIPCServer%3A%3AThreadPingEventReady%27%20AND%20product.Version%3D%2754.0.2840.59%27&ignore_case=false&enable_rewrite=true&omit_field_name=&omit_field_value=&omit_field_opt=%3D#samplereports:5,3rdparty,oncrashedthread,oncrashedthreadv,isinfected


Cc: krajshree@chromium.org
Labels: ReleaseBlock-Stable
So far seeing 2087 instances from 1954 different client ids.

Link to the list fo builds
https://crash.corp.google.com/browse?q=product.name%3D%27Chrome%27%20AND%20product.version%3D%2754.0.2840.59%27%20AND%20custom_data.ChromeCrashProto.ptype%3D%27browser%27%20AND%20custom_data.ChromeCrashProto.magic_signature_1.name%3D%27sandbox%3A%3ASharedMemIPCServer%3A%3AThreadPingEventReady%27&ignore_case=false&enable_rewrite=true&omit_field_name=&omit_field_value=&omit_field_opt=%3D

54.0.2840.59	83.78%	2087	

Adding stable blocker as seeing spike on M54.Please feel free to remove if not required.
Labels: pre-stable-54.0.2840.59

Comment 5 by lfg@chromium.org, Oct 17 2016

Owner: wfh@chromium.org
Re #2: This doesn't look like malware, but it does seem that some third-party dll is related to the crash.

+wfh, can you take a look?

Comment 6 by wfh@chromium.org, Oct 17 2016

Labels: -Restrict-View-Google
this appears to be a very old version of Citrix from 2012, having a bad interaction with Chrome 54.
Labels: -ReleaseBlock-Stable
Since we're already in Stable, I don't think this meets the bar for RBS.
Will - are you looking into what the interaction is? Should this be on sheriff queue?
Labels: -Type-Bug Type-Bug-Regression
So far seeing 5189 instances from 4638 different client ids on current beta 54.0.2840.59	

55.0.2883.11	0.07%	4	
55.0.2883.9	0.02%	1	
55.0.2882.4	0.04%	2	
55.0.2873.0	0.05%	3	
55.0.2871.0	0.02%	1	
55.0.2870.0	0.02%	1	
55.0.2868.3	0.07%	4	
55.0.2859.0	0.05%	3	
55.0.2847.0	0.02%	1	
54.0.2840.59	92.84%	5189	Beta
54.0.2840.50	0.11%	6	
54.0.2840.27	0.11%	6	
Experiencing this on Server 2008 R2 Citrix servers, Chrome V54.0.2840.71, even on the latest long-term release version of Citrix XenDesktop (7.6.300).  The app fails when running in a seamless window (works under a published desktop).  The crash does NOT occur on a Server 2012 R2 Citrix server; runs as expected.

This occurs with both 32-bit and 64-bit enterprise releases.

the '--no-sandbox' command switch will allow v54 to launch on the Server 2008 R2 servers, but with a warning message.
cgoffrie, are you running on production systems with --no-sandbox?  I'm not sure that would be a great idea.
To be more precise, this is #1 crasher for Win32 browser on the current stable version 54.0.2840.71.
I am not running on production system using --no-sandbox.  We are keeping our prod deployment at v51 Enterprise until this bug is worked out.  Just reporting all the results of my testing. :)
Just to update:

This is top #2 browser crash for Windows on the current stable version 54.0.2840.71 with 12835 instances from 10760 unique client Ids

Comment 16 by wfh@chromium.org, Oct 26 2016

This could be same root cause as  issue 659026 
Cc: ranjitkan@chromium.org
Labels: ReleaseBlock-Stable
Adding Release block label, since the instances in the stable are pretty high. Next stable is planned to be pushed soon. 

wfh@: Can you please take a look into it. Please undo or remove blocker label if not the case.

Instances on Current Stable 54.0.2840.71 - 19680:
=================================================
https://crash.corp.google.com/browse?q=product.name%3D%27Chrome%27%20AND%20custom_data.ChromeCrashProto.ptype%3D%27browser%27%20AND%20custom_data.ChromeCrashProto.magic_signature_1.name%3D%27sandbox%3A%3ASharedMemIPCServer%3A%3AThreadPingEventReady%27%20AND%20product.Version%3D%2754.0.2840.71%27&ignore_case=false&enable_rewrite=true&omit_field_name=&omit_field_value=&omit_field_opt=%3D

Note: So far no instances are reported on market beta 55.0.2883.28.


Thanks.!
Looks similar to  issue 659026  which is already fixed.
Keeping RB label for tracking purpose until the next stable update scheduled next week.

Comment 19 by wfh@chromium.org, Oct 31 2016

Mergedinto: 659026
Status: Duplicate (was: Assigned)

Sign in to add a comment