Issue metadata
Sign in to add a comment
|
Pages that were working in 59 crash Chrome 60 (geogebra.org applets)
Reported by
mich...@geogebra.at,
Aug 25 2017
|
||||||||||||||||||||||
Issue description
UserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.59 Safari/537.36
Steps to reproduce the problem:
This page crashes Chrome ("Aw, snap") immediately
https://www.geogebra.org/m/zVZm4KwY
This page crashes Chrome after the animation has run for a few seconds
https://www.geogebra.org/m/teaJZpR3
What is the expected behavior?
Both pages should display interactive applets
What went wrong?
"Aw, snap" error
Did this work before? Yes Chrome 59
Chrome version: 61.0.3163.59 Channel: beta
OS Version: 10.0
Flash Version: Shockwave Flash 26.0 r0
No problems in IE11, Edge, Firefox
,
Aug 28 2017
Also repros nicely on https://www.geogebra.org/m/teaJZpR3 and Linux.
,
Aug 28 2017
My crash ID: 317a95eecf9e27fd
,
Aug 29 2017
,
Aug 29 2017
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/a529f128a3c3a704773176f26b1238ee61c37b80 commit a529f128a3c3a704773176f26b1238ee61c37b80 Author: Jaroslav Sevcik <jarin@chromium.org> Date: Tue Aug 29 08:56:07 2017 [turbofan] Retype ConvertTaggedHoleToUndefined in representation selection. Bug: chromium:758983 Change-Id: Iea65c6c6330b4eed0969eee1f8b261e1446771f5 Reviewed-on: https://chromium-review.googlesource.com/640382 Commit-Queue: Jaroslav Sevcik <jarin@chromium.org> Commit-Queue: Benedikt Meurer <bmeurer@chromium.org> Reviewed-by: Benedikt Meurer <bmeurer@chromium.org> Cr-Commit-Position: refs/heads/master@{#47669} [modify] https://crrev.com/a529f128a3c3a704773176f26b1238ee61c37b80/src/compiler/operation-typer.cc [modify] https://crrev.com/a529f128a3c3a704773176f26b1238ee61c37b80/src/compiler/operation-typer.h [modify] https://crrev.com/a529f128a3c3a704773176f26b1238ee61c37b80/src/compiler/simplified-lowering.cc [modify] https://crrev.com/a529f128a3c3a704773176f26b1238ee61c37b80/src/compiler/typer.cc [add] https://crrev.com/a529f128a3c3a704773176f26b1238ee61c37b80/test/mjsunit/compiler/regress-758983.js
,
Aug 29 2017
,
Aug 30 2017
Thanks very much for the fast fix! Confirmed fixed for me in Version 62.0.3200.0 (Official Build) canary (64-bit) on Windows 10
,
Sep 9 2017
Is this fix going to make it into Chrome 61? I still have the bug in Version 61.0.3163.79 (Official Build) beta (64-bit) |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by schenney@chromium.org
, Aug 25 2017Status: Untriaged (was: Unconfirmed)