New issue
Advanced search Search tips

Issue 686766 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 685680
Owner: ----
Closed: Jan 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug



Sign in to add a comment

Segfault in v8::internal::compiler::EscapeStatusAnalysis::CheckUsesForEscape

Project Member Reported by danakj@chromium.org, Jan 30 2017

Issue description

Chrome Version: 58.0.2994.1
OS: Windows

https://crash/667de02880000000


0x00000000		
0x05c0a85e	(chrome_child.dll -escape-analysis.cc:840 )	v8::internal::compiler::EscapeStatusAnalysis::CheckUsesForEscape(v8::internal::compiler::Node *,v8::internal::compiler::Node *,bool)
0x05c0a952	(chrome_child.dll -escape-analysis.cc:861 )	v8::internal::compiler::EscapeStatusAnalysis::ProcessFinishRegion(v8::internal::compiler::Node *)
0x05c0a31f	(chrome_child.dll -escape-analysis.cc:674 )	v8::internal::compiler::EscapeStatusAnalysis::Process(v8::internal::compiler::Node *)
0x05c0a142	(chrome_child.dll -escape-analysis.cc:635 )	v8::internal::compiler::EscapeStatusAnalysis::RunStatusAnalysis()
0x05c0abd3	(chrome_child.dll -escape-analysis.cc:900 )	v8::internal::compiler::EscapeAnalysis::Run()
0x05c7dfb1	(chrome_child.dll -pipeline.cc:948 )	v8::internal::compiler::EscapeAnalysisPhase::Run(v8::internal::compiler::PipelineData *,v8::internal::Zone *)
0x05c8245d	(chrome_child.dll -pipeline.cc:711 )	v8::internal::compiler::PipelineImpl::Run<v8::internal::compiler::EscapeAnalysisPhase>()
0x05c7f8d4	(chrome_child.dll -pipeline.cc:1578 )	v8::internal::compiler::PipelineImpl::OptimizeGraph(v8::internal::compiler::Linkage *)
0x05c7cc20	(chrome_child.dll -pipeline.cc:618 )	v8::internal::compiler::PipelineCompilationJob::ExecuteJobImpl()
0x05bc4cf3	(chrome_child.dll -compiler.cc:118 )	v8::internal::CompilationJob::ExecuteJob()


Please see the minidump in the crash for details.
 

Comment 1 by danakj@chromium.org, Jan 30 2017

Cc: k...@luminance.org
Components: Blink>JavaScript

Comment 3 by danakj@chromium.org, Jan 30 2017

Here's a set of other crash reports that are (mostly?) all this same crash, from https://bugs.chromium.org/p/chromium/issues/detail?id=668892#c49:

Crash ID a8316a32-670e-4377-9f30-6983f55019d0 (Server ID: ab2c7e1580000000)

Crash report captured on Saturday, January 28, 2017 at 6:06:18 AM, uploaded on Saturday, January 28, 2017 at 6:07:34 AM

Provide additional details

Crash ID a08351cf-7826-46dd-a91d-2ed721ffc2c7 (Server ID: 024f4ca680000000)

Crash report captured on Saturday, January 28, 2017 at 6:05:17 AM, uploaded on Saturday, January 28, 2017 at 6:07:32 AM

Provide additional details

Crash ID 7087b2b3-d9a4-462b-a6a0-dad1cd6a2add (Server ID: 23402ca680000000)

Crash report captured on Saturday, January 28, 2017 at 5:59:55 AM, uploaded on Saturday, January 28, 2017 at 6:07:31 AM

Provide additional details

Crash ID 448838bd-f80d-48f8-af7b-4d813c7f0414 (Server ID: 8429d82880000000)

Crash report captured on Saturday, January 28, 2017 at 5:58:53 AM, uploaded on Saturday, January 28, 2017 at 6:07:30 AM

Provide additional details

Crash ID da3f36af-a042-46ab-8d3f-a2373b40ea08 (Server ID: d3d7be1580000000)

Crash report captured on Saturday, January 28, 2017 at 5:58:09 AM, uploaded on Saturday, January 28, 2017 at 5:58:56 AM

Provide additional details

Crash ID 68a50566-0559-4097-b29d-a367ba208a1f (Server ID: 19ac582880000000)

Crash report captured on Saturday, January 28, 2017 at 5:57:58 AM, uploaded on Saturday, January 28, 2017 at 5:58:54 AM

Provide additional details

Crash ID 7333c151-95b4-4cd3-9a3a-e8fa96fa92cd (Server ID: c1a07e1580000000)

Crash report captured on Saturday, January 28, 2017 at 5:57:04 AM, uploaded on Saturday, January 28, 2017 at 5:58:00 AM

Provide additional details

Crash ID 44011e60-9a1b-4da0-8b3b-d2015b526401 (Server ID: ab3fbe1580000000)

Crash report captured on Saturday, January 28, 2017 at 5:55:55 AM, uploaded on Saturday, January 28, 2017 at 5:57:59 AM

Provide additional details

Crash ID 2bf67a94-33f2-4354-aea2-5f51fdb0a576 (Server ID: 818c0ca680000000)

Crash report captured on Saturday, January 28, 2017 at 5:54:34 AM, uploaded on Saturday, January 28, 2017 at 5:56:02 AM

Provide additional details

Crash ID 8c7e1f17-9770-4cd2-83c4-8662f19fa763 (Server ID: 04fa982880000000)

Crash report captured on Saturday, January 28, 2017 at 5:53:33 AM, uploaded on Saturday, January 28, 2017 at 5:56:01 AM

Provide additional details

Crash ID b35474dd-1571-4bdc-82ac-fc79278792dc (Server ID: 8c88582880000000)

Crash report captured on Saturday, January 28, 2017 at 5:52:11 AM, uploaded on Saturday, January 28, 2017 at 5:56:00 AM

Provide additional details

Crash ID 4fc28b55-c53c-4b12-8057-9c857a8936c2 (Server ID: b62b982880000000)

Crash report captured on Saturday, January 28, 2017 at 5:43:52 AM, uploaded on Saturday, January 28, 2017 at 5:55:59 AM

Provide additional details

Crash ID a13a7cb1-5da6-4c7d-87b3-b1162113ad6c (Server ID: 0dd0982880000000)

Crash report captured on Saturday, January 28, 2017 at 5:38:17 AM, uploaded on Saturday, January 28, 2017 at 5:55:58 AM

Provide additional details

Crash ID 40657ddb-e039-4442-b6ee-f85c9ee638fd (Server ID: 3a03e4a680000000)

Crash report captured on Saturday, January 28, 2017 at 5:34:16 AM, uploaded on Saturday, January 28, 2017 at 5:34:17 AM

Provide additional details

Crash ID 860728c4-e012-4b11-807b-9b7301a00d3b (Server ID: c4f7be1580000000)

Crash report captured on Saturday, January 28, 2017 at 3:02:21 AM, uploaded on Saturday, January 28, 2017 at 5:55:56 AM

Provide additional details
Cc: hablich@chromium.org
hablich@ can you triage this? The CC team is working actively with an external party to triage a graphics issue and this dominating the crashes reported by this client id.

Comment 5 by k...@luminance.org, Jan 30 2017

If it helps, this game loads thousands of .js files over the network (via XHR), usually hitting cache, and then executes them in order to play back animations. It doesn't seem to do anything to cache them (i.e. new Function or closures), just executes them every time. So that's probably why I ended up hitting compiler crashes while playing - typically exactly when it started playing animations. The game tends to trigger reloads periodically, which I expect is to work around issues (memory leaks etc) caused by doing this and other sloppy things.

Comment 6 by k...@luminance.org, Jan 30 2017

For reference, here's one of the animation scripts (though it wasn't responsible for the crash, I just grabbed a representative one.)
ab_all_3040043000_01.js
43.8 KB View Download
Issue 684653 has been merged into this issue.
Mergedinto: 685680
Status: Duplicate (was: Untriaged)

Sign in to add a comment