Summary: | REGRESSION: Crash in com.apple.WebKit: IPC::Connection::sendMessage(std::__1::unique_ptr<IPC::MachMessage, std::__1::default_delete<IPC::MachMessage> >) + 27 | ||||||||
---|---|---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | Ryan Haddad <ryanhaddad> | ||||||
Component: | New Bugs | Assignee: | Anders Carlsson <andersca> | ||||||
Status: | RESOLVED FIXED | ||||||||
Severity: | Normal | CC: | andersca, webkit-bug-importer | ||||||
Priority: | P2 | Keywords: | InRadar | ||||||
Version: | WebKit Nightly Build | ||||||||
Hardware: | Unspecified | ||||||||
OS: | Unspecified | ||||||||
See Also: | https://bugs.webkit.org/show_bug.cgi?id=165866 | ||||||||
Attachments: |
|
Description
Ryan Haddad
2016-12-14 09:39:13 PST
Still seeing this crash frequently on perf tests. IndexedDB/objectstore-cursor.html crashed on this run: https://build.webkit.org/builders/Apple%20El%20Capitan%20Release%20WK2%20%28Perf%29/builds/3896/steps/perf-test/logs/stdio Seen here with LayoutTest accessibility/text-marker/character-offset-visible-position-conversion-hang.html: https://build.webkit.org/results/Apple%20El%20Capitan%20Release%20WK2%20(Tests)/r210038%20(11960)/results.html Started on 2016-12-09, and still happening. We are not getting the logging added in http://trac.webkit.org/r209831. I don't think that we are taking the code path that logging got added to. The crash is a segfault, not a trap. It seems to be crashing on message->size(), because message is a null pointer. Created attachment 298611 [details]
Patch
Comment on attachment 298611 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=298611&action=review > Source/WebKit2/Platform/IPC/mac/ConnectionMac.mm:403 > + // FIXME: Figure out why we get spurious DISPATCH_MACH_SEND_POSSIBLE events. Is there any logging we can add now to help diagnose? Committed r210596: <http://trac.webkit.org/changeset/210596> |