New issue
Advanced search Search tips

Issue 765929 link

Starred by 2 users

Issue metadata

Status: Duplicate
Owner:
Closed: Sep 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Compat



Sign in to add a comment

flash plugins is crashed when I visit douyu live video

Reported by terrydin...@gmail.com, Sep 16 2017

Issue description

UserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.91 Safari/537.36

Example URL:
https://www.douyu.com/154537

Steps to reproduce the problem:
1. open https://www.douyu.com/154537 in browser (other valid room numbers besides 154537 are fine)
or
1. open https://www.douyu.com/
2. enter in any live room which is listed on the home page  

What is the expected behavior?
The site plays flash video.

What went wrong?
flash is crashed

some message in the console is below:
[20145:20175:0916/222937.774442:ERROR:service_manager.cc(156)] Connection InterfaceProviderSpec prevented service: content_plugin from binding interface: memory_instrumentation::mojom::Coordinator exposed by: content_browser
[WARNING:flash/platform/pepper/pep_module.cpp(63)] SANDBOXED
[10243:10283:0916/222939.098967:FATAL:ppapi_blink_platform_impl.cc(92)] Check failed: creation_thread_ == base::PlatformThread::CurrentId() (10243 vs. 10283)
#0 0x556d4c47b656 <unknown>
#1 0x556d4c4946f2 <unknown>
#2 0x556d4c033003 <unknown>
#3 0x556d4e592f34 <unknown>
#4 0x556d4e59320f <unknown>
#5 0x556d4e58b736 <unknown>
#6 0x556d4e58bd65 <unknown>
#7 0x556d4e58c3f4 <unknown>
#8 0x556d4e640e6c <unknown>
#9 0x556d4e64313a <unknown>
#10 0x556d4e644280 <unknown>
#11 0x556d4e63f119 <unknown>
#12 0x556d4e596dc6 <unknown>
#13 0x556d4e576a56 <unknown>
#14 0x556d4e56c443 <unknown>
#15 0x556d4e4e9053 <unknown>
#16 0x556d4adda085 <unknown>
#17 0x7fefb2edef68 <unknown>
#18 0x7fefb2ee81be <unknown>
#19 0x7fefb2ee5724 <unknown>
#20 0x7fefb297c645 <unknown>
#21 0x7fefb26d7175 <unknown>
#22 0x7fefb26d7aff <unknown>
#23 0x7fefb26d8f75 <unknown>
#24 0x7fefb26d913f <unknown>
#25 0x7fefb27c2699 <unknown>
#26 0x7fefb2566d8b <unknown>
#27 0x0e87da484f2c <unknown>

Received signal 6
#0 0x556d4c47b656 <unknown>
#1 0x556d4a8e557a <unknown>
#2 0x556d4c47b9cc <unknown>
#3 0x7fefc775fda0 <unknown>
#4 0x7fefbf1408a0 __GI_raise
#5 0x7fefbf141f09 __GI_abort
#6 0x556d4c47b2c5 <unknown>
#7 0x556d4c4948c5 <unknown>
#8 0x556d4c033003 <unknown>
#9 0x556d4e592f34 <unknown>
#10 0x556d4e59320f <unknown>
#11 0x556d4e58b736 <unknown>
#12 0x556d4e58bd65 <unknown>
#13 0x556d4e58c3f4 <unknown>
#14 0x556d4e640e6c <unknown>
#15 0x556d4e64313a <unknown>
#16 0x556d4e644280 <unknown>
#17 0x556d4e63f119 <unknown>
#18 0x556d4e596dc6 <unknown>
#19 0x556d4e576a56 <unknown>
#20 0x556d4e56c443 <unknown>
#21 0x556d4e4e9053 <unknown>
#22 0x556d4adda085 <unknown>
#23 0x7fefb2edef68 <unknown>
#24 0x7fefb2ee81be <unknown>
#25 0x7fefb2ee5724 <unknown>
#26 0x7fefb297c645 <unknown>
#27 0x7fefb26d7175 <unknown>
#28 0x7fefb26d7aff <unknown>
#29 0x7fefb26d8f75 <unknown>
#30 0x7fefb26d913f <unknown>
#31 0x7fefb27c2699 <unknown>
#32 0x7fefb2566d8b <unknown>
#33 0x0e87da484f2c <unknown>
  r8: 0000000000000000  r9: 00007fefadc25ee0 r10: 0000000000000008 r11: 0000000000000246
 r12: 00007fefadc263a0 r13: 000000000000009d r14: 00007fefadc26390 r15: 00007fefadc263b0
  di: 0000000000000002  si: 00007fefadc25ee0  bp: 00007fefadc26380  bx: 0000000000000006
  dx: 0000000000000000  ax: 0000000000000000  cx: 00007fefbf1408a0  sp: 00007fefadc25ee0
  ip: 00007fefbf1408a0 efl: 0000000000000246 cgf: 002b000000000033 erf: 0000000000000000
 trp: 0000000000000000 msk: 0000000000000000 cr2: 0000000000000000
[end of stack trace]
Calling _exit(1). Core file will not be generated.

Does it occur on multiple sites: No

Is it a problem with a plugin? Yes flash

Did this work before? Yes chromium-60.0.3112.113-1-x86_64.pkg.tar.xz  in archlinux package repo.

Does this work in other browsers? Yes

Chrome version: 61.0.3163.91  Channel: stable
OS Version: archlinux
Flash Version: Shockwave Flash 27.0 r0

I can visit other flash sites which use flash to play video.
And the home page of douyu.com can show the live video as well.
But just the specific live room is crashed. 

When I downgrade the chromium to version 60(without any other change), the problem is disappeared.
 
douyu home page is fine.png
1.5 MB View Download
douyu specific room is crashed.png
238 KB View Download
Labels: Needs-Triage-M61 Needs-Bisect
Components: Internals>Plugins>Flash
Labels: Triaged-ET M-61
Able to reproduce the issue on version 61.0.3163.91 using Ubuntu 14.04 and on latest canary 63.0.3218.0 with steps mentioned in Comment#0

As its a Regression issue broken in M-61, please find Manual Bisect info as follows:
===============
Good Build:61.0.3142.0 (482491)
Bad Build:61.0.3143.0 (482834)

Crash report ID of Linux: 070b8e442a3e0fa2 

Note: Issue is not reproducible on Win 10 and Mac 10.12.1 on version 63.0.3218.0

As tool bisect is invoking all the good build and as per revision bisect set up is not available on Linux, hence updating manual bisect info

Status: Untriaged (was: Unconfirmed)

Comment 4 by ajha@chromium.org, Sep 18 2017

Cc: ajha@chromium.org
Components: Blink>Fonts
Labels: -Pri-2 -Needs-Bisect hasbisect-per-revision Pri-1
Owner: fs...@chromium.org
Status: Assigned (was: Untriaged)
Ran the per revision bisect of this.

https://chromium.googlesource.com/chromium/src/+log/5a480d9f206dc6d114a163ee91d157dbeb782209..958810932f8b93831d919b8915c3c916db559636

Stack trace of 070b8e442a3e0fa2 : go/crash/070b8e442a3e0fa2  (Not pasting the content here as the stack trace contains confidential infn.) 

Comment 5 by fs...@chromium.org, Sep 19 2017

Cc: drott@chromium.org
Drott,

do you have any idea why this change:
https://chromium-review.googlesource.com/c/chromium/src/+/544690

ends up triggering the GetFallbackFontForCharacter on the wrong thread?
I feel like removing the check, but I don't want to do so without understanding it a bit.

Comment 6 by fs...@chromium.org, Sep 19 2017

Mergedinto: 755120
Status: Duplicate (was: Assigned)

Sign in to add a comment