New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 847023 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Aug 4
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Bug-Regression



Sign in to add a comment

ClusterFuzz crash updating bookmark bar layer tree

Project Member Reported by ClusterFuzz, May 26 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=6097470384504832

Fuzzer: meacer_extension_apis
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: Ill
Crash Address: 0x7fff98bbbe6a
Crash State:
  -
  -
  __handleUncaughtException
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=561913:561932

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6097470384504832

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, May 26 2018

Labels: Fuzz-Blocker ReleaseBlock-Beta M-69
This crash occurs very frequently on mac platform and is likely preventing the fuzzer meacer_extension_apis from making much progress. Fixing this will allow more bugs to be found.

Marking this bug as a blocker for next Beta release.

If this is incorrect, please add ClusterFuzz-Wrong label and remove the ReleaseBlock-Beta label.
Project Member

Comment 2 by ClusterFuzz, May 26 2018

Components: UI>Browser>Bookmarks
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
sem acesso
Project Member

Comment 4 by ClusterFuzz, May 27 2018

Labels: -Reproducible Unreproducible
ClusterFuzz testcase 6097470384504832 appears to be flaky, updating reproducibility label.
Cc: brajkumar@chromium.org
Components: -UI>Browser>Bookmarks Blink>WebRTC
Labels: -Type-Bug Test-Predator-Wrong Type-Bug-Regression
Owner: eladalon@chromium.org
Status: Assigned (was: Untriaged)
Predator and CL could not provide any possible suspects.

Using Code Search for the file, "webrtc_event_log_manager.cc" suspecting the below Cl might have caused this issue

Suspect CL: https://chromium.googlesource.com/chromium/src/+/3ef52273644384b0c6201773c1c235fd7a345ccf%5E%21/chrome/browser/media/webrtc/webrtc_event_log_manager.cc

eladalon@ -- Could you please check whether this is caused with respect to your change, if not please help us in assigning it to the right owner.

Thanks!

Comment 6 by gov...@chromium.org, Jun 18 2018

M69 branch is coming soon on July 19th, Your bug is marked as ReleaseBlock-Beta for M69. Please try to land the fix ASAP to trunk in order to prevent many merges going after M69 branch. This will also help us to branch M69 from high quality trunk. Thank you.


Cc: terelius@chromium.org
Sorry, I've not seen this before, for some reason. Let me have a look.
Cc: weili@chromium.org ellyjo...@chromium.org ligim...@chromium.org
Labels: -ReleaseBlock-Beta
Wondering whether the crash is due to mac views. Seeing some bookmark controller stack frames in the report. Wei, would you mind confirming?

https://chromium-review.googlesource.com/c/chromium/src/+/1041141

Stack trace which I am referring to the report link in #0.

	0   CoreFoundation                      0x00007fff8ea384f2 __exceptionPreprocess + 178
1   Chromium Framework                  0x00000001157d6796 _ZN6chromeL25ObjcExceptionPreprocessorEP11objc_object + 2326
2   libobjc.A.dylib                     0x00007fff85fec73c objc_exception_throw + 48
3   CoreFoundation                      0x00007fff8ea9f4bd +[NSException raise:format:] + 205
4   QuartzCore                          0x00007fff8d9d19b6 _ZN2CA5Layer12set_positionERKNS_4Vec2IdEEb + 152
5   QuartzCore                          0x00007fff8d9d1916 -[CALayer setPosition:] + 44
6   AppKit                              0x00007fff99130759 -[NSView(NSInternal) _updateLayerGeometryFromView] + 2970
7   AppKit                              0x00007fff9912fafa -[NSView(NSInternal) _updateAllLayerPropertiesFromView] + 132
8   AppKit                              0x00007fff9912f633 -[NSView setLayer:] + 910
9   AppKit                              0x00007fff9912ece3 -[NSView(NSInternal) _createLayerAndInitialize] + 208
10  AppKit                              0x00007fff9912fbe6 -[NSView(NSInternal) _updateLayerGeometryFromView] + 39
11  AppKit                              0x00007fff9913f1e5 -[NSView _gainedLayerTreeHostAncestor] + 352
12  AppKit                              0x00007fff9913f06f -[NSView _recursiveGainedLayerTreeHostAncestor] + 27
13  AppKit                              0x00007fff99102349 -[NSView _setSuperview:] + 1693
14  AppKit                              0x00007fff99101814 -[NSView addSubview:] + 448
15  Chromium Framework                  0x0000000120067125 -[BookmarkBarController createAppsPageShortcutButton] + 1093
16  Chromium Framework                  0x0000000120067c05 -[BookmarkBarController createExtraButtons] + 149
17  Chromium Framework                  0x0000000120071531 -[BookmarkBarController loaded:] + 305
18  Chromium Framework                  0x000000011c3dd2f2 _ZN9bookmarks13BookmarkModel11DoneLoadingENSt3__110unique_ptrINS_19BookmarkLoadDetailsENS1_14default_deleteIS3_EEEE + 3394
19  Chromium Framework                  0x000000011c3f4743 _ZN4base8internal7InvokerINS0_9BindStateIMN9bookmarks13BookmarkModelEFvNSt3__110unique_ptrINS3_19BookmarkLoadDetailsENS5_14default_deleteIS7_EEEEEJNS_7WeakPtrIS4_EEEEEFvSA_EE7RunOnceEPNS0_13BindStateBaseEOSA_ + 611
20  Chromium Framework                  0x000000011c422b10 _ZN9bookmarks11ModelLoader14OnFinishedLoadENSt3__110unique_ptrINS_19BookmarkLoadDetailsENS1_14default_deleteIS3_EEEEN4base12OnceCallbackIFvS6_EEE + 336
21  Chromium Framework                  0x000000011c423563 _ZN4base8internal7InvokerINS0_9BindStateIMN9bookmarks11ModelLoaderEFvNSt3__110unique_ptrINS3_19BookmarkLoadDetailsENS5_14default_deleteIS7_EEEENS_12OnceCallbackIFvSA_EEEEJ13scoped_refptrIS4_ESA_SD_EEEFvvEE7RunOnceEPNS0_13BindStateBaseE + 499

Also looping to Elly who reviewed the above CL.

Removing the RB label as the test appears to be flaky.
Maybe assign to more likely owner?
Owner: ----
Status: Untriaged (was: Assigned)
Components: -Blink>WebRTC UI>Browser>Bookmarks
Labels: CF-NeedsTriage
Unable to provide possible suspect using Predator, CL and Code Search.
Could someone please look into the issue.

Thank You...
Labels: -Pri-1 Hotlist-CocoaBrowser Pri-2
Status: Available (was: Untriaged)
Summary: ClusterFuzz crash updating bookmark bar layer tree (was: Ill in -)
#8: I don't think it was that CL.

My reading of this bug so far is that we've observed this crash on ClusterFuzz but don't have a reliable repro case and haven't seen it from the field. Is that right? If so I'm going to lower the priority.

Is there a crash/ crash? We're going to need the "lastexception" crash keys to figure out what the heck is going on, or a working local repro.

Also, this bug is Cocoa-specific (BookmarkBarController is only used in Cocoa) so it is not likely we will prioritize this unless it is majorly blocking work elsewhere.
Project Member

Comment 14 by ClusterFuzz, Aug 4

Status: WontFix (was: Available)
ClusterFuzz testcase 6097470384504832 is flaky and no longer crashes, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment