New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 756836 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Sep 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Regression

Blocked on:
issue 752185



Sign in to add a comment

whenever i try to check or remove cookies flash crashes

Reported by unclezil...@gmail.com, Aug 18 2017

Issue description

UserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.101 Safari/537.36

Steps to reproduce the problem:
1. settings
2. advanced
3. content settings, cookies = crash

What is the expected behavior?
flash crashes and has done the same for 3 months now despite many reports

What went wrong?
crash 

Crashed report ID:  f22af0e72c2bb006

How much crashed? Just one tab

Is it a problem with a plugin? N/A 

Did this work before? N/A 

Chrome version: 60.0.3112.101  Channel: stable
OS Version: 
Flash Version: Shockwave Flash 26.0 r0
 
this problem has persisted for some months

Comment 2 by hdodda@chromium.org, Aug 21 2017

Cc: u...@chromium.org hdodda@chromium.org
Components: Blink>JavaScript
Labels: -Type-Bug -Pri-2 Needs-Triage-M60 Restrict-View-Google Pri-1 Type-Bug-Regression
Based on the crash id and stack trace , marking dev in cc for further inputs on this.

Stack Trace :
=------------

Thread 0 (id: 19446) CRASHED [SIGILL @ 0x000055e4644f4630 ] MAGIC SIGNATURE THREAD
Stack Quality67%Show frame trust levels
0x000055e4644f4630	(chrome -V8Initializer.cpp:87 )	blink::ReportOOMErrorInMainThread(char const*, bool)
0x000055e46075539b	(chrome -api.cc:421 )	v8::Utils::ReportOOMFailure(char const*, bool)
0x000055e460755351	(chrome -api.cc:384 )	<name omitted>
0x000055e460b1ac73	(chrome -sequential-marking-deque.cc:84 )	v8::internal::SequentialMarkingDeque::EnsureCommitted()
0x000055e460b1ab6a	(chrome -sequential-marking-deque.cc:33 )	v8::internal::SequentialMarkingDeque::StartUsing()
0x000055e460ae23e7	(chrome -mark-compact.cc:3059 )	v8::internal::MarkCompactCollector::MarkLiveObjects()
0x000055e460ae20d5	(chrome -mark-compact.cc:451 )	v8::internal::MarkCompactCollector::CollectGarbage()
0x000055e460ac5e6b	(chrome -heap.cc:1486 )	v8::internal::Heap::MarkCompact()
0x000055e460ac4ed0	(chrome -heap.cc:1345 )	v8::internal::Heap::PerformGarbageCollection(v8::internal::GarbageCollector, v8::GCCallbackFlags)
0x000055e460ac3c67	(chrome -heap.cc:1023 )	v8::internal::Heap::CollectGarbage(v8::internal::GarbageCollector, v8::internal::GarbageCollectionReason, char const*, v8::GCCallbackFlags)
0x000055e460acbe36	(chrome -heap-inl.h:681 )	v8::internal::Heap::ReserveSpace(std::vector<v8::internal::Heap::Chunk, std::allocator<v8::internal::Heap::Chunk> >*, v8::internal::List<unsigned char*, v8::internal::FreeStoreAllocationPolicy>*)
0x000055e460d59984	(chrome -deserializer.cc:64 )	v8::internal::Deserializer::DeserializePartial(v8::internal::Isolate*, v8::internal::Handle<v8::internal::JSGlobalProxy>, v8::DeserializeInternalFieldsCallback)
0x000055e460d52ef1	(chrome -snapshot-common.cc:66 )	v8::internal::Snapshot::NewContextFromSnapshot(v8::internal::Isolate*, v8::internal::Handle<v8::internal::JSGlobalProxy>, unsigned long, v8::DeserializeInternalFieldsCallback)
0x000055e4607b0a51	(chrome -bootstrapper.cc:5075 )	v8::internal::Genesis::Genesis(v8::internal::Isolate*, v8::internal::MaybeHandle<v8::internal::JSGlobalProxy>, v8::Local<v8::ObjectTemplate>, unsigned long, v8::DeserializeInternalFieldsCallback, v8::internal::GlobalContextType)
0x000055e4607b07f0	(chrome -bootstrapper.cc:284 )	v8::internal::Bootstrapper::CreateEnvironment(v8::internal::MaybeHandle<v8::internal::JSGlobalProxy>, v8::Local<v8::ObjectTemplate>, v8::ExtensionConfiguration*, unsigned long, v8::DeserializeInternalFieldsCallback, v8::internal::GlobalContextType)
0x000055e460755dbb	(chrome -api.cc:6371 )	v8::NewContext(v8::Isolate*, v8::ExtensionConfiguration*, v8::MaybeLocal<v8::ObjectTemplate>, v8::MaybeLocal<v8::Value>, unsigned long, v8::DeserializeInternalFieldsCallback)
0x000055e460757d2c	(chrome -api.cc:6513 )	v8::Context::New(v8::Isolate*, v8::ExtensionConfiguration*, v8::MaybeLocal<v8::ObjectTemplate>, v8::MaybeLocal<v8::Value>)
0x000055e46450c652	(chrome -LocalWindowProxy.cpp:197 )	blink::LocalWindowProxy::CreateContext()
0x000055e46450c15f	(chrome -LocalWindowProxy.cpp:131 )	blink::LocalWindowProxy::Initialize()
0x000055e4633f71a4	(chrome -WindowProxyManager.h:47 )	blink::Frame::GetWindowProxy(blink::DOMWrapperWorld&)
0x000055e46450ebde	(chrome -ToV8ForCore.cpp:33 )	blink::ToV8(blink::DOMWindow*, v8::Local<v8::Object>, v8::Isolate*)
0x000055e4645952df	(chrome -V8BindingForCore.h:140 )	blink::V8Window::crossOriginIndexedGetter(unsigned int, v8::PropertyCallbackInfo<v8::Value> const&)
0x000055e460b3b3c7	(chrome -api-arguments-inl.h:66 )	<name omitted>
0x000055e460bacf6a	(chrome -objects.cc:1691 )	v8::internal::(anonymous namespace)::GetPropertyAttributesWithInterceptorInternal(v8::internal::LookupIterator*, v8::internal::Handle<v8::internal::InterceptorInfo>)
0x000055e460bb33e7	(chrome -objects.cc:997 )	v8::internal::JSReceiver::HasProperty(v8::internal::LookupIterator*)
0x000055e460cf7774	(chrome -objects-inl.h:7487 )	v8::internal::Runtime_HasProperty(int, v8::internal::Object**, v8::internal::Isolate*)
0x000027fae8e846fc		
0x000027fae8f8474d		
0x000027fae8f3f054		
0x000027fae8e85d7a		
0x000027fae8f7aa41		
0x000027fae8f3f054		
0x000027fae8f7aa41		
0x000027fae8f3f054		
0x000027fae8e85d7a		
0x000027fae8f79907		
0x000027fae8f3f054		
0x000027fae8e85d7a		
0x000027faec884e65		
0x000027fae8e85d7a		
0x000027fae8f7aa41		
0x000027fae8f3f054		
0x000027fae8f7a8f1		
0x000027fae8f3f054		
0x000027fae8e85d7a		
0x000027fae8f7a0a9		
0x000027fae8f3f054		
0x000027fae8e85d7a		
0x000027fae8f7a8f1		
0x000027fae8f3f054		
0x000027fae8e85d7a		
0x000027faeb7225d7		
0x000027fae8f3e318		
0x000027fae8e8412c		
0x000055e460a85381	(chrome -execution.cc:145 )	v8::internal::(anonymous namespace)::Invoke(v8::internal::Isolate*, bool, v8::internal::Handle<v8::internal::Object>, v8::internal::Handle<v8::internal::Object>, int, v8::internal::Handle<v8::internal::Object>*, v8::internal::Handle<v8::internal::Object>, v8::internal::Execution::MessageHandling)
0x000055e460a85104	(chrome -execution.cc:181 )	v8::internal::Execution::Call(v8::internal::Isolate*, v8::internal::Handle<v8::internal::Object>, v8::internal::Handle<v8::internal::Object>, int, v8::internal::Handle<v8::internal::Object>*)
0x000055e46076b8a6	(chrome -api.cc:5270 )	v8::Function::Call(v8::Local<v8::Context>, v8::Local<v8::Value>, int, v8::Local<v8::Value>*)
0x000055e4644fa989	(chrome -V8ScriptRunner.cpp:680 )	blink::V8ScriptRunner::CallFunction(v8::Local<v8::Function>, blink::ExecutionContext*, v8::Local<v8::Value>, int, v8::Local<v8::Value>*, v8::Isolate*)
0x000055e4645100b8	(chrome -V8EventListener.cpp:115 )	<name omitted>
0x000055e46450f396	(chrome -V8AbstractEventListener.cpp:146 )	blink::V8AbstractEventListener::InvokeEventHandler(blink::ScriptState*, blink::Event*, v8::Local<v8::Value>)
0x000055e46450f185	(chrome -V8AbstractEventListener.cpp:104 )	blink::V8AbstractEventListener::HandleEvent(blink::ScriptState*, blink::Event*)
0x000055e46450ef86	(chrome -V8AbstractEventListener.cpp:92 )	blink::V8AbstractEventListener::handleEvent(blink::ExecutionContext*, blink::Event*)
0x000055e4633e7a80	(chrome -EventTarget.cpp:725 )	blink::EventTarget::FireEventListeners(blink::Event*, blink::EventTargetData*, blink::HeapVector<blink::RegisteredEventListener, 1ul>&)
0x000055e4633e6b92	(chrome -EventTarget.cpp:585 )	blink::EventTarget::FireEventListeners(blink::Event*)
0x000055e4633e0b8e	(chrome -EventDispatcher.cpp:204 )	blink::EventDispatcher::Dispatch()
0x000055e4633e0058	(chrome -EventDispatcher.cpp:59 )	blink::EventDispatcher::DispatchEvent(blink::Node&, blink::EventDispatchMediator*)
0x000055e463419be4	(chrome -LocalDOMWindow.cpp:1539 )	blink::LocalDOMWindow::DispatchLoadEvent()
0x000055e46341a29b	(chrome -LocalDOMWindow.cpp:408 )	blink::LocalDOMWindow::DocumentWasClosed()
0x000055e46481005f	(chrome -Document.cpp:3062 )	blink::Document::ImplicitClose()
0x000055e46480fcb5	(chrome -Document.cpp:3156 )	blink::Document::CheckCompleted()
0x000055e46480febf	(chrome -Document.cpp:3178 )	blink::Document::CheckCompleted()
0x000055e460f5d64a	(chrome -ResourceFetcher.cpp:1273 )	blink::ResourceFetcher::HandleLoaderFinish(blink::Resource*, double, blink::ResourceFetcher::LoaderFinishType)
0x000055e4644a134d	(chrome -web_url_loader_impl.cc:906 )	content::WebURLLoaderImpl::Context::OnCompletedRequest(int, bool, bool, base::TimeTicks const&, long, long, long)
0x000055e4632a47cd	(chrome -resource_dispatcher.cc:373 )	content::ResourceDispatcher::OnRequestComplete(int, content::ResourceRequestCompletionStatus const&)
0x000055e4632a495a	(chrome -tuple.h:77 )	bool IPC::MessageT<ResourceMsg_RequestComplete_Meta, std::tuple<int, content::ResourceRequestCompletionStatus>, void>::Dispatch<content::ResourceDispatcher, content::ResourceDispatcher, void, void (content::ResourceDispatcher::*)(int, content::ResourceRequestCompletionStatus const&)>(IPC::Message const*, content::ResourceDispatcher*, content::ResourceDispatcher*, void*, void (content::ResourceDispatcher::*)(int, content::ResourceRequestCompletionStatus const&))
0x000055e4632a25ca	(chrome -resource_dispatcher.cc:534 )	content::ResourceDispatcher::DispatchMessage(IPC::Message const&)
0x000055e4632a0bb5	(chrome -resource_dispatcher.cc:134 )	content::ResourceDispatcher::OnMessageReceived(IPC::Message const&)
0x000055e4632a60e5	(chrome -resource_scheduling_filter.cc:74 )	content::ResourceSchedulingFilter::DispatchMessage(IPC::Message const&)
0x000055e461413a4f	(chrome -callback.h:91 )	base::debug::TaskAnnotator::RunTask(char const*, base::PendingTask*)
0x000055e4633cfc7d	(chrome -task_queue_manager.cc:531 )	blink::scheduler::TaskQueueManager::ProcessTaskFromWorkQueue(blink::scheduler::internal::WorkQueue*, bool, blink::scheduler::LazyNow, base::TimeTicks*)
0x000055e4633cf027	(chrome -task_queue_manager.cc:329 )	blink::scheduler::TaskQueueManager::DoWork(bool)
0x000055e461413a4f	(chrome -callback.h:91 )	base::debug::TaskAnnotator::RunTask(char const*, base::PendingTask*)
0x000055e4613a810f	(chrome -message_loop.cc:409 )	base::MessageLoop::RunTask(base::PendingTask*)
0x000055e4613a8567	(chrome -message_loop.cc:420 )	base::MessageLoop::DeferOrRunPendingTask(base::PendingTask)
0x000055e4613a7b85	(chrome -message_loop.cc:508 )	base::MessageLoop::DoWork()
0x000055e4613a9484	(chrome -message_pump_default.cc:33 )	base::MessagePumpDefault::Run(base::MessagePump::Delegate*)
0x000055e4613c715d	(chrome -run_loop.cc:111 )	base::RunLoop::Run()
0x000055e463901d5b	(chrome -renderer_main.cc:219 )	content::RendererMain(content::MainFunctionParams const&)
0x000055e46103725e	(chrome -content_main_runner.cc:341 )	content::RunZygote(content::MainFunctionParams const&, content::ContentMainDelegate*)
0x000055e461038264	(chrome -content_main_runner.cc:705 )	content::ContentMainRunnerImpl::Run()
0x000055e46103eda0	(chrome -main.cc:469 )	service_manager::Main(service_manager::MainParams const&)
0x000055e461037001	(chrome -content_main.cc:19 )	content::ContentMain(content::ContentMainParams const&)
0x000055e45fc026fb	(chrome -chrome_main.cc:109 )	ChromeMain
0x00007f76ae72282f	(libc-2.23.so + 0x0002082f )	
0x000055e45fc0265f	(chrome + 0x00b8a65f )	SyscallAsm
0x000055e45fc02503	(chrome -os2.cc:103 )	__cxx_global_array_dtor


@ulan -- Could you please look into this , if this might have affected your recent chnages in the file "sequential-marking-deque.cc".

Thanks!

Comment 3 by u...@chromium.org, Aug 21 2017

Blockedon: 752185
Labels: -Restrict-View-Google
Owner: u...@chromium.org
Status: Assigned (was: Unconfirmed)
This is most likely caused by sandbox restrictions on the renderer process that limits heap to 2GB.

Comment 4 by u...@chromium.org, Aug 21 2017

Labels: -Needs-Triage-M60

Comment 5 by u...@chromium.org, Aug 30 2017

Owner: ----

Comment 6 by u...@chromium.org, Aug 30 2017

Status: Available (was: Assigned)

Comment 7 by cbruni@chromium.org, Sep 28 2017

Status: WontFix (was: Available)
All the submitted reports are out of memory bugs after more than 2h uptime.
I don't think this is actionable.

I'll close the issue for now,  unclezillion pleas feel free add more info and reopen.

Sign in to add a comment