MJPEG stream with empty frame crashes tab
Reported by
syriusa...@gmail.com,
Sep 1 2017
|
|||||||
Issue descriptionUserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/60.0.3112.78 Chrome/60.0.3112.78 Safari/537.36 Example URL: Steps to reproduce the problem: 1. Start attached server.py (python3 server.py) 2. Open attached test.html in a chrome browser 3. Tab crashes with 'Aw, Snap!' What is the expected behavior? No crash What went wrong? The attached MJPEG_640x480.http file contains a brief capture of a HTTP MJPEG stream from a camera. The first frame in the stream is an empty frame with no size. This crashes the browser immediately. The stream may not be completely valid but should not cause a crash. Did this work before? N/A Is it a problem with Flash or HTML5? HTML5 Does this work in other browsers? Yes Chrome version: 60.0.3112.78 Channel: n/a OS Version: 16.04 Flash Version: Shockwave Flash 25.0 r0 Contents of chrome://gpu: Graphics Feature Status Canvas: Hardware accelerated CheckerImaging: Disabled Flash: Hardware accelerated Flash Stage3D: Hardware accelerated Flash Stage3D Baseline profile: Hardware accelerated Compositing: Hardware accelerated Multiple Raster Threads: Enabled Native GpuMemoryBuffers: Software only. Hardware acceleration disabled Rasterization: Software only. Hardware acceleration disabled Video Decode: Software only, hardware acceleration unavailable Video Encode: Software only, hardware acceleration unavailable WebGL: Hardware accelerated WebGL2: Hardware accelerated Driver Bug Workarounds clear_uniforms_before_first_program_use decode_encode_srgb_for_generatemipmap disable_discard_framebuffer disable_framebuffer_cmaa force_cube_complete init_gl_position_in_vertex_shader init_vertex_attributes pack_parameters_workaround_with_pack_buffer scalarize_vec_and_mat_constructor_args unpack_alignment_workaround_with_unpack_buffer unpack_overlapping_rows_separately_unpack_buffer use_virtualized_gl_contexts Problems Detected Accelerated video decode is unavailable on Linux: 137247 Disabled Features: accelerated_video_decode Accelerated video encode is unavailable on Linux Disabled Features: accelerated_video_encode Program link fails in NVIDIA Linux if gl_Position is not set: 286468 Applied Workarounds: init_gl_position_in_vertex_shader Clear uniforms before first program use on all platforms: 124764, 349137 Applied Workarounds: clear_uniforms_before_first_program_use Linux NVIDIA drivers don't have the correct defaults for vertex attributes: 351528 Applied Workarounds: init_vertex_attributes Always rewrite vec/mat constructors to be consistent: 398694 Applied Workarounds: scalarize_vec_and_mat_constructor_args MakeCurrent is slow on Linux with NVIDIA drivers: 449150, 514510 Applied Workarounds: use_virtualized_gl_contexts NVIDIA drivers before 346 lack features in NV_path_rendering and related extensions to implement driver level path rendering.: 344330 NVIDIA fails glReadPixels from incomplete cube map texture: 518889 Applied Workarounds: force_cube_complete Pack parameters work incorrectly with pack buffer bound: 563714 Applied Workarounds: pack_parameters_workaround_with_pack_buffer Alignment works incorrectly with unpack buffer bound: 563714 Applied Workarounds: unpack_alignment_workaround_with_unpack_buffer Framebuffer discarding can hurt performance on non-tilers: 570897 Applied Workarounds: disable_discard_framebuffer Unpacking overlapping rows from unpack buffers is unstable on NVIDIA GL driver: 596774 Applied Workarounds: unpack_overlapping_rows_separately_unpack_buffer Limited enabling of Chromium GL_INTEL_framebuffer_CMAA: 535198 Applied Workarounds: disable_framebuffer_cmaa Decode and encode before generateMipmap for srgb format textures on os except macosx: 634519 Applied Workarounds: decode_encode_srgb_for_generatemipmap Disable KHR_blend_equation_advanced until cc shaders are updated: 661715 Accelerated rasterization has been disabled, either via blacklist, about:flags or the command line. Disabled Features: rasterization Native GpuMemoryBuffers have been disabled, either via about:flags or command line. Disabled Features: native_gpu_memory_buffers Checker-imaging has been disabled via finch trial or the command line. Disabled Features: checker_imaging Version Information Data exported 9/1/2017, 9:59:35 AM Chrome version Chrome/60.0.3112.78 Operating system Linux 4.4.0-91-generic Software rendering list version 13.8 Driver bug list version 10.93 ANGLE commit id unknown hash 2D graphics backend Skia/60 a20ae70af542208b06c21413f13c4c86269c0b84- Command Line /usr/lib/chromium-browser/chromium-browser --ppapi-flash-path=/usr/lib/pepperflashplugin-nonfree/libpepflashplayer.so --ppapi-flash-version=25.0.0.127 --enable-pinch --flag-switches-begin --flag-switches-end Driver Information Initialization time 5287 In-process GPU false Passthrough Command Decoder false Supports overlays false Sandboxed true GPU0 VENDOR = 0x10de, DEVICE= 0x0a65 Optimus false Optimus false AMD switchable false Driver vendor Nvidia Driver version 340.102 Driver date Pixel shader version 3.30 Vertex shader version 3.30 Max. MSAA samples 16 Machine model name Machine model version GL_VENDOR NVIDIA Corporation GL_RENDERER GeForce 210/PCIe/SSE2 GL_VERSION 3.3.0 NVIDIA 340.102 GL_EXTENSIONS GL_ARB_arrays_of_arrays GL_ARB_base_instance GL_ARB_blend_func_extended GL_ARB_clear_buffer_object GL_ARB_color_buffer_float GL_ARB_compressed_texture_pixel_storage GL_ARB_conservative_depth GL_ARB_copy_buffer GL_ARB_copy_image GL_ARB_debug_output GL_ARB_depth_buffer_float GL_ARB_depth_clamp GL_ARB_depth_texture GL_ARB_draw_buffers GL_ARB_draw_buffers_blend GL_ARB_draw_elements_base_vertex GL_ARB_draw_instanced GL_ARB_enhanced_layouts GL_ARB_ES2_compatibility GL_ARB_ES3_compatibility GL_ARB_explicit_attrib_location GL_ARB_explicit_uniform_location GL_ARB_fragment_coord_conventions GL_ARB_fragment_layer_viewport GL_ARB_fragment_program GL_ARB_fragment_program_shadow GL_ARB_fragment_shader GL_ARB_framebuffer_no_attachments GL_ARB_framebuffer_object GL_ARB_framebuffer_sRGB GL_ARB_geometry_shader4 GL_ARB_get_program_binary GL_ARB_half_float_pixel GL_ARB_half_float_vertex GL_ARB_imaging GL_ARB_instanced_arrays GL_ARB_internalformat_query GL_ARB_internalformat_query2 GL_ARB_invalidate_subdata GL_ARB_map_buffer_alignment GL_ARB_map_buffer_range GL_ARB_multi_bind GL_ARB_multisample GL_ARB_multitexture GL_ARB_occlusion_query GL_ARB_occlusion_query2 GL_ARB_pixel_buffer_object GL_ARB_point_parameters GL_ARB_point_sprite GL_ARB_program_interface_query GL_ARB_provoking_vertex GL_ARB_robust_buffer_access_behavior GL_ARB_robustness GL_ARB_sample_shading GL_ARB_sampler_objects GL_ARB_seamless_cube_map GL_ARB_separate_shader_objects GL_ARB_shader_bit_encoding GL_ARB_shader_objects GL_ARB_shader_texture_lod GL_ARB_shading_language_100 GL_ARB_shading_language_420pack GL_ARB_shading_language_include GL_ARB_shading_language_packing GL_ARB_shadow GL_ARB_stencil_texturing GL_ARB_sync GL_ARB_texture_border_clamp GL_ARB_texture_buffer_object GL_ARB_texture_buffer_range GL_ARB_texture_compression GL_ARB_texture_compression_rgtc GL_ARB_texture_cube_map GL_ARB_texture_cube_map_array GL_ARB_texture_env_add GL_ARB_texture_env_combine GL_ARB_texture_env_crossbar GL_ARB_texture_env_dot3 GL_ARB_texture_float GL_ARB_texture_gather GL_ARB_texture_mirror_clamp_to_edge GL_ARB_texture_mirrored_repeat GL_ARB_texture_multisample GL_ARB_texture_non_power_of_two GL_ARB_texture_query_levels GL_ARB_texture_query_lod GL_ARB_texture_rectangle GL_ARB_texture_rg GL_ARB_texture_rgb10_a2ui GL_ARB_texture_stencil8 GL_ARB_texture_storage GL_ARB_texture_storage_multisample GL_ARB_texture_swizzle GL_ARB_texture_view GL_ARB_timer_query GL_ARB_transform_feedback2 GL_ARB_transform_feedback_instanced GL_ARB_transpose_matrix GL_ARB_uniform_buffer_object GL_ARB_vertex_array_bgra GL_ARB_vertex_array_object GL_ARB_vertex_attrib_binding GL_ARB_vertex_buffer_object GL_ARB_vertex_program GL_ARB_vertex_shader GL_ARB_vertex_type_10f_11f_11f_rev GL_ARB_vertex_type_2_10_10_10_rev GL_ARB_viewport_array GL_ARB_window_pos GL_ATI_draw_buffers GL_ATI_texture_float GL_ATI_texture_mirror_once GL_S3_s3tc GL_EXT_texture_env_add GL_EXT_abgr GL_EXT_bgra GL_EXT_bindable_uniform GL_EXT_blend_color GL_EXT_blend_equation_separate GL_EXT_blend_func_separate GL_EXT_blend_minmax GL_EXT_blend_subtract GL_EXT_compiled_vertex_array GL_EXT_Cg_shader GL_EXT_depth_bounds_test GL_EXT_direct_state_access GL_EXT_draw_buffers2 GL_EXT_draw_instanced GL_EXT_draw_range_elements GL_EXT_fog_coord GL_EXT_framebuffer_blit GL_EXT_framebuffer_multisample GL_EXTX_framebuffer_mixed_formats GL_EXT_framebuffer_multisample_blit_scaled GL_EXT_framebuffer_object GL_EXT_framebuffer_sRGB GL_EXT_geometry_shader4 GL_EXT_gpu_program_parameters GL_EXT_gpu_shader4 GL_EXT_multi_draw_arrays GL_EXT_packed_depth_stencil GL_EXT_packed_float GL_EXT_packed_pixels GL_EXT_pixel_buffer_object GL_EXT_point_parameters GL_EXT_provoking_vertex GL_EXT_rescale_normal GL_EXT_secondary_color GL_EXT_separate_shader_objects GL_EXT_separate_specular_color GL_EXT_shader_integer_mix GL_EXT_shadow_funcs GL_EXT_stencil_two_side GL_EXT_stencil_wrap GL_EXT_texture3D GL_EXT_texture_array GL_EXT_texture_buffer_object GL_EXT_texture_compression_dxt1 GL_EXT_texture_compression_latc GL_EXT_texture_compression_rgtc GL_EXT_texture_compression_s3tc GL_EXT_texture_cube_map GL_EXT_texture_edge_clamp GL_EXT_texture_env_combine GL_EXT_texture_env_dot3 GL_EXT_texture_filter_anisotropic GL_EXT_texture_integer GL_EXT_texture_lod GL_EXT_texture_lod_bias GL_EXT_texture_mirror_clamp GL_EXT_texture_object GL_EXT_texture_shared_exponent GL_EXT_texture_sRGB GL_EXT_texture_sRGB_decode GL_EXT_texture_storage GL_EXT_texture_swizzle GL_EXT_timer_query GL_EXT_transform_feedback2 GL_EXT_vertex_array GL_EXT_vertex_array_bgra GL_EXT_x11_sync_object GL_EXT_import_sync_object GL_IBM_rasterpos_clip GL_IBM_texture_mirrored_repeat GL_KHR_debug GL_KTX_buffer_region GL_NV_blend_square GL_NV_conditional_render GL_NV_copy_depth_to_color GL_NV_copy_image GL_NV_depth_buffer_float GL_NV_depth_clamp GL_NV_ES1_1_compatibility GL_NV_explicit_multisample GL_NV_fence GL_NV_float_buffer GL_NV_fog_distance GL_NV_fragment_program GL_NV_fragment_program_option GL_NV_fragment_program2 GL_NV_framebuffer_multisample_coverage GL_NV_geometry_shader4 GL_NV_gpu_program4 GL_NV_gpu_program4_1 GL_NV_half_float GL_NV_light_max_exponent GL_NV_multisample_coverage GL_NV_multisample_filter_hint GL_NV_occlusion_query GL_NV_packed_depth_stencil GL_NV_parameter_buffer_object GL_NV_parameter_buffer_object2 GL_NV_pixel_data_range GL_NV_point_sprite GL_NV_primitive_restart GL_NV_register_combiners GL_NV_register_combiners2 GL_NV_shader_buffer_load GL_NV_texgen_reflection GL_NV_texture_barrier GL_NV_texture_compression_vtc GL_NV_texture_env_combine4 GL_NV_texture_expand_normal GL_NV_texture_multisample GL_NV_texture_rectangle GL_NV_texture_shader GL_NV_texture_shader2 GL_NV_texture_shader3 GL_NV_transform_feedback GL_NV_transform_feedback2 GL_NV_vdpau_interop GL_NV_vertex_array_range GL_NV_vertex_array_range2 GL_NV_vertex_buffer_unified_memory GL_NV_vertex_program GL_NV_vertex_program1_1 GL_NV_vertex_program2 GL_NV_vertex_program2_option GL_NV_vertex_program3 GL_NVX_conditional_render GL_NVX_gpu_memory_info GL_SGIS_generate_mipmap GL_SGIS_texture_lod GL_SGIX_depth_texture GL_SGIX_shadow GL_SUN_slice_accum Disabled Extensions GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent GL_NV_path_rendering Window system binding vendor NVIDIA Corporation Window system binding version 1.4 Window system binding extensions GLX_EXT_visual_info GLX_EXT_visual_rating GLX_SGIX_fbconfig GLX_SGIX_pbuffer GLX_SGI_video_sync GLX_SGI_swap_control GLX_EXT_swap_control GLX_EXT_swap_control_tear GLX_EXT_texture_from_pixmap GLX_EXT_buffer_age GLX_ARB_create_context GLX_ARB_create_context_profile GLX_EXT_create_context_es_profile GLX_EXT_create_context_es2_profile GLX_ARB_create_context_robustness GLX_NV_delay_before_swap GLX_EXT_stereo_tree GLX_ARB_multisample GLX_NV_float_buffer GLX_ARB_fbconfig_float GLX_EXT_framebuffer_sRGB GLX_NV_multisample_coverage Window manager Compiz XDG_CURRENT_DESKTOP MATE GDMSESSION mate Compositing manager Yes Direct rendering Yes Reset notification strategy 0x8252 GPU process crash count 0 System visual ID 33 RGBA visual ID 178 Compositor Information Tile Update Mode One-copy Partial Raster Enabled GpuMemoryBuffers Status ATC Software only ATCIA Software only DXT1 Software only DXT5 Software only ETC1 Software only R_8 Software only RG_88 Software only BGR_565 Software only RGBA_4444 Software only RGBX_8888 Software only RGBA_8888 Software only BGRX_8888 Software only BGRA_8888 Software only RGBA_F16 Software only YVU_420 Software only YUV_420_BIPLANAR Software only UYVY_422 Software only Log Messages [6277:6339:0901/084352.730390:WARNING:x11_util.cc(1366)] : X error received: serial 546, error_code 3 (BadWindow), request_code 4, minor_code 0 (Unknown) [6277:6339:0901/084407.293204:WARNING:x11_util.cc(1366)] : X error received: serial 1117, error_code 3 (BadWindow), request_code 4, minor_code 0 (Unknown) [6277:6339:0901/094216.407087:WARNING:x11_util.cc(1366)] : X error received: serial 188554, error_code 3 (BadWindow), request_code 4, minor_code 0 (Unknown) [6277:6339:0901/094221.257078:WARNING:x11_util.cc(1366)] : X error received: serial 188953, error_code 3 (BadWindow), request_code 4, minor_code 0 (Unknown) [6277:6277:0901/094245.728440:ERROR:gles2_cmd_decoder.cc(17721)] : [.DisplayCompositor-0x557274892ea0]GL ERROR :GL_INVALID_OPERATION : glCreateAndConsumeTextureCHROMIUM: invalid mailbox name [6277:6277:0901/094245.728525:ERROR:gles2_cmd_decoder.cc(9728)] : [.DisplayCompositor-0x557274892ea0]RENDER WARNING: texture bound to texture unit 0 is not renderable. It maybe non-power-of-2 and have incompatible texture filtering. [6277:6277:0901/094245.728675:ERROR:gles2_cmd_decoder.cc(17721)] : [.DisplayCompositor-0x557274892ea0]GL ERROR :GL_INVALID_OPERATION : glCreateAndConsumeTextureCHROMIUM: invalid mailbox name [6277:6277:0901/094245.728722:ERROR:gles2_cmd_decoder.cc(9728)] : [.DisplayCompositor-0x557274892ea0]RENDER WARNING: texture bound to texture unit 0 is not renderable. It maybe non-power-of-2 and have incompatible texture filtering. [6277:6339:0901/094715.396319:WARNING:x11_util.cc(1366)] : X error received: serial 205611, error_code 3 (BadWindow), request_code 4, minor_code 0 (Unknown) [6277:6277:0901/095112.091648:ERROR:gles2_cmd_decoder.cc(17721)] : [.DisplayCompositor-0x557274892ea0]GL ERROR :GL_INVALID_OPERATION : glCreateAndConsumeTextureCHROMIUM: invalid mailbox name [6277:6277:0901/095112.091736:ERROR:gles2_cmd_decoder.cc(9728)] : [.DisplayCompositor-0x557274892ea0]RENDER WARNING: texture bound to texture unit 0 is not renderable. It maybe non-power-of-2 and have incompatible texture filtering. [6277:6277:0901/095112.091881:ERROR:gles2_cmd_decoder.cc(17721)] : [.DisplayCompositor-0x557274892ea0]GL ERROR :GL_INVALID_OPERATION : glCreateAndConsumeTextureCHROMIUM: invalid mailbox name [6277:6277:0901/095112.091945:ERROR:gles2_cmd_decoder.cc(9728)] : [.DisplayCompositor-0x557274892ea0]RENDER WARNING: texture bound to texture unit 0 is not renderable. It maybe non-power-of-2 and have incompatible texture filtering. [6277:6277:0901/095112.092002:ERROR:gles2_cmd_decoder.cc(17721)] : [.DisplayCompositor-0x557274892ea0]GL ERROR :GL_INVALID_OPERATION : glCreateAndConsumeTextureCHROMIUM: invalid mailbox name [6277:6277:0901/095112.092052:ERROR:gles2_cmd_decoder.cc(9728)] : [.DisplayCompositor-0x557274892ea0]RENDER WARNING: texture bound to texture unit 0 is not renderable. It maybe non-power-of-2 and have incompatible texture filtering. [6277:6277:0901/095112.092107:ERROR:gles2_cmd_decoder.cc(17721)] : [.DisplayCompositor-0x557274892ea0]GL ERROR :GL_INVALID_OPERATION : glCreateAndConsumeTextureCHROMIUM: invalid mailbox name [6277:6277:0901/095112.092156:ERROR:gles2_cmd_decoder.cc(9728)] : [.DisplayCompositor-0x557274892ea0]RENDER WARNING: texture bound to texture unit 0 is not renderable. It maybe non-power-of-2 and have incompatible texture filtering. [6277:6339:0901/095808.144374:WARNING:x11_util.cc(1366)] : X error received: serial 247385, error_code 3 (BadWindow), request_code 4, minor_code 0 (Unknown) [6277:6339:0901/095816.042464:WARNING:x11_util.cc(1366)] : X error received: serial 247872, error_code 3 (BadWindow), request_code 4, minor_code 0 (Unknown) [6277:6339:0901/095819.409035:WARNING:x11_util.cc(1366)] : X error received: serial 248107, error_code 3 (BadWindow), request_code 4, minor_code 0 (Unknown) [6277:6339:0901/095919.111529:WARNING:x11_util.cc(1366)] : X error received: serial 251108, error_code 3 (BadWindow), request_code 4, minor_code 0 (Unknown) [6277:6339:0901/095926.527092:WARNING:x11_util.cc(1366)] : X error received: serial 251531, error_code 3 (BadWindow), request_code 4, minor_code 0 (Unknown) Tested on: Google Chrome Version 60.0.3112.90 (Official Build) (64-bit) - Ubuntu MATE 16.04 Chromium Version 60.0.3112.78 (Developer Build) (64-bit) - Ubuntu MATE 16.04 Google Chrome Version 60.0.3112.113 (Official Build) (32-bit) - Windows 7
,
Sep 5 2017
,
Sep 5 2017
,
Sep 6 2017
Thank you for reporting and providing the test case! I reproduced the crash with the test case on Chrome 60.0.3112.113 Stable on Windows 7 and Linux. The crash server reports different crashing lines: - CHECK(false) for transition from kNotStarted on Windows (ID 1affe7b1a6953330), and - CHECK(false) for transition from kLoadError/kDecodeError on Linux (ID: 5f91ff6776484027). Probably, the line reported for Windows Chrome is wrong, due to compiler optimization etc?
,
Sep 6 2017
Requesting merge of the fix mentioned in Comment #1, which is the fix for Issue 737392 (https://crbug.com/737392#c9) to M-60 again, as requested by hdodda@. The situation change since the previous request (https://crbug.com/737392#c19): - According to my Comment https://crbug.com/737392#c29, the CL seems to fix broader range of crashes than I thought before (https://crbug.com/737392#c21). The numbers of crashes on M-60 potentially affected by the fix are: 60.0.3112.116 0.52% 34 60.0.3112.113 22.83% 1491 60.0.3112.107 7.65% 500 60.0.3112.101 28.78% 1880 60.0.3112.97 0.46% 30 60.0.3112.90 31.80% 207 QUERY: custom_data.ChromeCrashProto.magic_signature_1.name='blink::ImageResourceContent::UpdateToLoadedContentStatus' - This Issue 761272 is filed. - The fix is landed on M-61 but is not merged to M-60. - This is a crashing bug but not a security issue. - The fix CL is small and probably is safe to be merged because it just removes a CHECK(false) call in certain cases. M-60 merge owners, could you take a look whether the fix is worth being merged to M-60, or can/should we wait for M-61 stable promotion?
,
Sep 6 2017
,
Sep 11 2017
Er, M-61 has already been promoted to stable. As the fix is already included in M-61 stable, closing as fixed. |
|||||||
►
Sign in to add a comment |
|||||||
Comment 1 by hdodda@chromium.org
, Sep 5 2017Labels: hasbisect-per-revision Needs-Triage-M60 M-61 OS-Windows
Owner: hirosh...@chromium.org
Status: Assigned (was: Unconfirmed)