New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 773177 link

Starred by 1 user

Issue metadata

Status: Assigned
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Mac
Pri: 1
Type: Bug-Regression



Sign in to add a comment

Print crash

Reported by wadih.ma...@gmail.com, Oct 10 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36

Steps to reproduce the problem:
1.http://localhost/run.html 
2.click on "click"

What is the expected behavior?
No crash

What went wrong?
Null pointer dereference crash

Crashed report ID: 

How much crashed? Just one tab

Is it a problem with a plugin? No 

Did this work before? N/A 

Chrome version: 63.0.3236.0 (Official Build) canary (64 bits)  Channel: stable
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version:
 
poc.zip
810 bytes Download
Cc: vamshi.k...@techmahindra.com
Labels: Needs-Feedback Triaged-ET Needs-Triage-M63
After navigating to the given path http://localhost/run.html , it's refusing to connect to the host. We tried with the zip file attached it isn't showing anything and it's not crashing too. Attaching the screencast of the same.

@Reporter: Could you plese mention if we have missed any steps to reproduce the issue. It would be highly helpful if given crash ID for further triaging.

Thanks!
773177.ogv
1.4 MB View Download
Maybe your web server listens on a different port.

This repro only works for me on canary windows 64 bits, it doesn't reproduce on the stable version (although i have seen the same crash on the stable version before).

This is the crash i get:

Access violation - code c0000005 (first chance)
First chance exceptions are reported before any exception handling.
This exception may be expected and handled.
chrome_child!blink::WebRemoteFrameImpl::AddReplicatedContentSecurityPolicyHeader+0x1e:
000007fe`d8edf102 488b4868        mov     rcx,qword ptr [rax+68h] ds:00000000`00000068=????????????????
Project Member

Comment 3 by sheriffbot@chromium.org, Oct 10 2017

Labels: -Needs-Feedback
Thank you for providing more feedback. Adding requester "vamshi.kommuri@techmahindra.com" to the cc list and removing "Needs-Feedback" label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Cc: jmukthavaram@chromium.org mkwst@chromium.org
Labels: -Type-Bug -Pri-2 hasbisect-per-revision M-63 OS-Linux OS-Mac Pri-1 Type-Bug-Regression
Owner: japhet@chromium.org
Status: Assigned (was: Unconfirmed)
Able to reproduce this issue on windows 7, Mac 10.12.6,Linux Ubuntu 14.04 with Chrome reported version-63.0.3236.0 as per below steps:
1. Download above zip file & extract zip file
2. Open terminal & run below command
     python -m SimpleHTTPServer 
3. Launch chrome
4. Type as below on new tab & click enter
     http://localhost:8000/ path of the downloaded file  (http://localhost:8000/downloads/run.html)
5. Observe 'Click' button
6. Click on that button
7. Crash observed on new tab page ( 2.html)

Manual Bisect:
-------------
Good Build—63.0.3232.0 -Revision-506256
Bad Build—63.0.3233.0 -Revision-506599

Bisect Tool Info:
----------------
You are probably looking for a change made after 506443 (known good), but no later than 506444 (first known bad).
CHANGELOG URL:
The script might not always return single CL as suspectas some perf builds might get missing due to failure.
https://chromium.googlesource.com/chromium/src/+log/4dccf5d1c1bf257fdf600271404a8dd8d6d06fc6..3ecbb0c68cd72a8f2a9ef16691e6c13c9b80d0fc

Possible suspect:
----------------
https://chromium.googlesource.com/chromium/src/+/3ecbb0c68cd72a8f2a9ef16691e6c13c9b80d0fc

japhet@,Kindly take a look and please help us to reassign this issue to a right owner if not with respect to this change.

Thanks.!
Components: Blink>Loader

Sign in to add a comment