Bug 996032

Summary: openSUSE Tumbleweed 20160826: Chromium crashes systematically when loading certain web pages
Product: [openSUSE] openSUSE Tumbleweed Reporter: Forgotten User wW9bm8F8VI <forgotten_wW9bm8F8VI>
Component: OtherAssignee: Forgotten User sM9JzehKpy <forgotten_sM9JzehKpy>
Status: RESOLVED FIXED QA Contact: E-mail List <qa-bugs>
Severity: Major    
Priority: P5 - None CC: bingmybong, forgotten_bg4zyG8wID, forgotten_vbObYCuz9U, forgotten__AcwqRqvKw, jmatejek, jon, stefan.kunze
Version: Current   
Target Milestone: ---   
Hardware: x86-64   
OS: openSUSE 42.1   
Whiteboard:
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Forgotten User wW9bm8F8VI 2016-08-29 14:03:55 UTC
When loading e.g. http://money.usnews.com/investing/articles/2016-08-18/twitter-inc-facebook-inc-twtr-fb-quietly-destroying, Chromium displays "Aw, Snap! Something went wrong while displaying this webpage.". This also happens with many other web pages.

$ rpm -qf /usr/bin/chromium
chromium-52.0.2743.116-1.1.x86_64
Comment 1 Forgotten User wW9bm8F8VI 2016-08-29 14:09:15 UTC
The output that was produced when I started chromium --enable-logging --v=1 http://www.xe.com/currencycharts/?from=EUR&to=USD&view=1W:

(chromium:4742): IBUS-WARNING **: Unable to connect to ibus: Could not connect: Connection refused                                                                                                                                                                             
[4742:4742:0829/070741:ERROR:browser_main_loop.cc(277)] gdkwindow-x11.c:5555 drawable is not a native X11 window (http://crbug.com/329991)                                                                                                                                     
[4742:4742:0829/070741:ERROR:browser_main_loop.cc(277)] gdkwindow-x11.c:5555 drawable is not a native X11 window (http://crbug.com/329991)                                                                                                                                     
[4742:4742:0829/070741:ERROR:browser_main_loop.cc(277)] gdkwindow-x11.c:5555 drawable is not a native X11 window (http://crbug.com/329991)                                                                                                                                     
Received signal 11 SEGV_MAPERR 000000000020                                                                                                                                                                                                                                    
#0 0x5616b9f9757e base::debug::StackTrace::StackTrace()                                                                                                                                                                                                                        
#1 0x5616b9f97939 base::debug::(anonymous namespace)::StackDumpSignalHandler()                                                                                                                                                                                                 
#2 0x7f98d0a1bef0 <unknown>                                                                                                                                                                                                                                                    
#3 0x5616b959d5a5 blink::LayoutObject::isDescendantOf()                                                                                                                                                                                                                        
#4 0x5616b961a01c blink::CompositedLayerMapping::containingSquashedLayer()                                                                                                                                                                                                     
#5 0x5616b96201eb blink::CompositingLayerAssigner::getReasonsPreventingSquashing()                                                                                                                                                                                             
#6 0x5616b962114e blink::CompositingLayerAssigner::assignLayersToBackingsInternal()                                                                                                                                                                                            
#7 0x5616b9620e51 blink::CompositingLayerAssigner::assignLayersToBackingsInternal()                                                                                                                                                                                            
#8 0x5616b9620e51 blink::CompositingLayerAssigner::assignLayersToBackingsInternal()                                                                                                                                                                                            
#9 0x5616b9621231 blink::CompositingLayerAssigner::assign()                                                                                                                                                                                                                    
#10 0x5616b96254f9 blink::PaintLayerCompositor::updateIfNeeded()                                                                                                                                                                                                               
#11 0x5616b9626956 blink::PaintLayerCompositor::updateIfNeededRecursiveInternal()                                                                                                                                                                                              
#12 0x5616b9626b9c blink::PaintLayerCompositor::updateIfNeededRecursive()                                                                                                                                                                                                      
#13 0x5616b9263e52 blink::FrameView::updateLifecyclePhasesInternal()                                                                                                                                                                                                           
#14 0x5616b93c502d blink::PageAnimator::updateAllLifecyclePhases()                                                                                                                                                                                                             
#15 0x5616b8a03f9a blink::WebViewImpl::updateAllLifecyclePhases()                                                                                                                                                                                                              
#16 0x5616b9d16593 content::RenderWidgetCompositor::UpdateLayerTreeHost()                                                                                                                                                                                                      
#17 0x5616b6610226 cc::ProxyMain::BeginMainFrame()                                                                                                                                                                                                                             
#18 0x5616b6619100 _ZN4base8internal7InvokerINS_13IndexSequenceIJLm0ELm1EEEENS0_9BindStateINS0_15RunnableAdapterIMN2cc9ProxyMainEFvSt10unique_ptrINS6_28BeginMainFrameAndCommitStateESt14default_deleteIS9_EEEEEFvPS7_SC_EJRNS_7WeakPtrIS7_EENS0_13PassedWrapperISC_EEEEENS0_12InvokeHelperILb1EvSF_EEFvvEE3RunEPNS0_13BindStateBaseE                                                                                                                                                                                                                         
#19 0x5616b9f98e3d base::debug::TaskAnnotator::RunTask()                                                                                                                                                                                                                       
#20 0x5616b8659daf scheduler::TaskQueueManager::ProcessTaskFromWorkQueue()                                                                                                                                                                                                     
#21 0x5616b865a3b4 scheduler::TaskQueueManager::DoWork()                                                                                                                                                                                                                       
#22 0x5616b8657ceb _ZN4base8internal7InvokerINS_13IndexSequenceIJLm0ELm1ELm2EEEENS0_9BindStateINS0_15RunnableAdapterIMN9scheduler16TaskQueueManagerEFvNS_9TimeTicksEbEEEFvPS7_S8_bEJNS_7WeakPtrIS7_EERS8_bEEENS0_12InvokeHelperILb1EvSB_EEFvvEE3RunEPNS0_13BindStateBaseE      
#23 0x5616b9f98e3d base::debug::TaskAnnotator::RunTask()                                                                                                                                                                                                                       
#24 0x5616b9fb64ae base::MessageLoop::RunTask()                                                                                                                                                                                                                                
#25 0x5616b9fb717d base::MessageLoop::DeferOrRunPendingTask()                                                                                                                                                                                                                  
#26 0x5616b9fb7450 base::MessageLoop::DoWork()                                                                                                                                                                                                                                 
#27 0x5616b9fb8d89 base::MessagePumpDefault::Run()                                                                                                                                                                                                                             
#28 0x5616b9fd6bea base::RunLoop::Run()                                                                                                                                                                                                                                        
#29 0x5616b9fb57f5 base::MessageLoop::Run()                                                                                                                                                                                                                                    
#30 0x5616b9daeb30 content::RendererMain()                                                                                                                                                                                                                                     
#31 0x5616b9f71df4 content::RunZygote()                                                                                                                                                                                                                                        
#32 0x5616b9f7236f content::ContentMainRunnerImpl::Run()                                                                                                                                                                                                                       
#33 0x5616b9f705f1 content::ContentMain()                                                                                                                                                                                                                                      
#34 0x5616b5471d3a ChromeMain                                                                                                                                                                                                                                                  
#35 0x7f98d0689741 __libc_start_main                                                                                                                                                                                                                                           
#36 0x5616b5471bd9 _start                                                                                                                                                                                                                                                      
  r8: 0000000000000294  r9: 00000000000001dd r10: 0000000000000035 r11: 0000000000000020                                                                                                                                                                                       
 r12: 00002012c4b05b98 r13: 0000000000000007 r14: 0000000000000000 r15: 00001b2351a0c000                                                                                                                                                                                       
  di: 0000000000000000  si: 00001b2351a26500  bp: 0000000000000000  bx: 0000000000000000                                                                                                                                                                                       
  dx: 0000000000000007  ax: 00001b2351a0e8a0  cx: 0000000000000195  sp: 00007ffecfd55a38                                                                                                                                                                                       
  ip: 00005616b959d5a5 efl: 0000000000010287 cgf: 002b000000000033 erf: 0000000000000004                                                                                                                                                                                       
 trp: 000000000000000e msk: 0000000000000000 cr2: 0000000000000020                                                                                                                                                                                                             
[end of stack trace]
Comment 2 Forgotten User wW9bm8F8VI 2016-08-29 14:11:53 UTC
A quote from https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=833501:

Build with gcc 5 during the gcc 6 transition (closes: #833501).
Comment 3 Forgotten User vbObYCuz9U 2016-08-29 22:52:13 UTC
I think I am hit by this bug too on TW.


# rpm -qf /usr/bin/chromium
chromium-52.0.2743.116-1.1.x86_64

# zypper se -s chromium
Loading repository data...
Reading installed packages...

S | Name                           | Type       | Version           | Arch   | Repository
--+--------------------------------+------------+-------------------+--------+-----------
  | chromium                       | srcpackage | 52.0.2743.116-1.1 | noarch | Packman
i | chromium                       | package    | 52.0.2743.116-1.1 | x86_64 | TW-OSS 
v | chromium                       | package    | 52.0.2743.116-1.1 | i586   | TW-OSS 
  | chromium-beta                  | srcpackage | 53.0.2785.80-21.1 | noarch | Packman
  | chromium-beta-ffmpeg           | package    | 53.0.2785.80-21.1 | x86_64 | Packman
  | chromium-beta-ffmpeg           | package    | 53.0.2785.80-21.1 | i586   | Packman
  | chromium-beta-ffmpeg-debuginfo | package    | 53.0.2785.80-21.1 | x86_64 | Packman
  | chromium-beta-ffmpeg-debuginfo | package    | 53.0.2785.80-21.1 | i586   | Packman
  | chromium-bsu                   | package    | 0.9.15.1-2.1      | x86_64 | TW-OSS 
  | chromium-bsu                   | package    | 0.9.15.1-2.1      | i586   | TW-OSS 
i | chromium-desktop-gnome         | package    | 52.0.2743.116-1.1 | x86_64 | TW-OSS 
v | chromium-desktop-gnome         | package    | 52.0.2743.116-1.1 | i586   | TW-OSS 
  | chromium-desktop-kde           | package    | 52.0.2743.116-1.1 | x86_64 | TW-OSS 
  | chromium-desktop-kde           | package    | 52.0.2743.116-1.1 | i586   | TW-OSS
  | chromium-dev                   | srcpackage | 54.0.2837.0-25.1  | noarch | Packman
  | chromium-dev-ffmpeg            | package    | 54.0.2837.0-25.1  | x86_64 | Packman
  | chromium-dev-ffmpeg            | package    | 54.0.2837.0-25.1  | i586   | Packman
  | chromium-dev-ffmpeg-debuginfo  | package    | 54.0.2837.0-25.1  | x86_64 | Packman
  | chromium-dev-ffmpeg-debuginfo  | package    | 54.0.2837.0-25.1  | i586   | Packman
i | chromium-ffmpeg                | package    | 52.0.2743.116-1.1 | x86_64 | Packman
v | chromium-ffmpeg                | package    | 52.0.2743.116-1.1 | i586   | Packman
  | chromium-ffmpeg-debuginfo      | package    | 52.0.2743.116-1.1 | x86_64 | Packman
  | chromium-ffmpeg-debuginfo      | package    | 52.0.2743.116-1.1 | i586   | Packman
  | chromium-ffmpegsumo            | package    | 52.0.2743.116-1.1 | x86_64 | TW-OSS
  | chromium-ffmpegsumo            | package    | 52.0.2743.116-1.1 | i586   | TW-OSS
i | chromium-pepper-flash          | package    | 22.0.0.209-4.1    | x86_64 | Packman
v | chromium-pepper-flash          | package    | 22.0.0.209-4.1    | i586   | Packman
  | chromium-pepper-flash          | srcpackage | 22.0.0.209-4.1    | noarch | Packman
  | chromium-plugin-widevinecdm    | package    | 1.4.8.893-1.1     | x86_64 | Packman
  | chromium-plugin-widevinecdm    | srcpackage | 1.4.8.893-1.1     | noarch | Packman


LOG when visiting gfycat.com:

Received signal 11 SEGV_MAPERR 000000000020
#0 0x5624d8b3857e base::debug::StackTrace::StackTrace()
#1 0x5624d8b38939 base::debug::(anonymous namespace)::StackDumpSignalHandler()
#2 0x7f0dc7720ef0 <unknown>
#3 0x5624d813e5a5 blink::LayoutObject::isDescendantOf()
#4 0x5624d81bb01c blink::CompositedLayerMapping::containingSquashedLayer()
#5 0x5624d81c11eb blink::CompositingLayerAssigner::getReasonsPreventingSquashing()
#6 0x5624d81c214e blink::CompositingLayerAssigner::assignLayersToBackingsInternal()
#7 0x5624d81c1e51 blink::CompositingLayerAssigner::assignLayersToBackingsInternal()
#8 0x5624d81c1e51 blink::CompositingLayerAssigner::assignLayersToBackingsInternal()
#9 0x5624d81c2231 blink::CompositingLayerAssigner::assign()
#10 0x5624d81c64f9 blink::PaintLayerCompositor::updateIfNeeded()
#11 0x5624d81c7956 blink::PaintLayerCompositor::updateIfNeededRecursiveInternal()
#12 0x5624d81c7b9c blink::PaintLayerCompositor::updateIfNeededRecursive()
#13 0x5624d7e04e52 blink::FrameView::updateLifecyclePhasesInternal()
#14 0x5624d7f6602d blink::PageAnimator::updateAllLifecyclePhases()
#15 0x5624d75a4f9a blink::WebViewImpl::updateAllLifecyclePhases()
#16 0x5624d88b7593 content::RenderWidgetCompositor::UpdateLayerTreeHost()
#17 0x5624d51b1226 cc::ProxyMain::BeginMainFrame()
#18 0x5624d51ba100 _ZN4base8internal7InvokerINS_13IndexSequenceIJLm0ELm1EEEENS0_9BindStateINS0_15RunnableAdapterIMN2cc9ProxyMainEFvSt10unique_ptrINS6_28BeginMainFrameAndCommitStateESt14default_deleteIS9_EEEEEFvPS7_SC_EJRNS_7WeakPtrIS7_EENS0_13PassedWrapperISC_EEEEENS0_12InvokeHelperILb1EvSF_EEFvvEE3RunEPNS0_13BindStateBaseE
#19 0x5624d8b39e3d base::debug::TaskAnnotator::RunTask()
#20 0x5624d71fadaf scheduler::TaskQueueManager::ProcessTaskFromWorkQueue()
#21 0x5624d71fb3b4 scheduler::TaskQueueManager::DoWork()
#22 0x5624d71f8e4b _ZN4base8internal7InvokerINS_13IndexSequenceIJLm0ELm1ELm2EEEENS0_9BindStateINS0_15RunnableAdapterIMN9scheduler16TaskQueueManagerEFvNS_9TimeTicksEbEEEFvPS7_S8_bEJNS_7WeakPtrIS7_EES8_bEEENS0_12InvokeHelperILb1EvSB_EEFvvEE3RunEPNS0_13BindStateBaseE
#23 0x5624d8b39e3d base::debug::TaskAnnotator::RunTask()
#24 0x5624d8b574ae base::MessageLoop::RunTask()
#25 0x5624d8b5817d base::MessageLoop::DeferOrRunPendingTask()
#26 0x5624d8b58450 base::MessageLoop::DoWork()
#27 0x5624d8b59d89 base::MessagePumpDefault::Run()
#28 0x5624d8b77bea base::RunLoop::Run()
#29 0x5624d8b567f5 base::MessageLoop::Run()
#30 0x5624d894fb30 content::RendererMain()
#31 0x5624d8b12df4 content::RunZygote()
#32 0x5624d8b1336f content::ContentMainRunnerImpl::Run()
#33 0x5624d8b115f1 content::ContentMain()
#34 0x5624d4012d3a ChromeMain
#35 0x7f0dc7388741 __libc_start_main
#36 0x5624d4012bd9 _start
  r8: 0000000000000447  r9: 000000000000032c r10: 0000000000000000 r11: 00001f6455dae250
 r12: 00001f134c90c608 r13: 0000000000000001 r14: 0000000000000000 r15: 00002c43c880c000
  di: 0000000000000000  si: 00002c43c882ef40  bp: 0000000000000000  bx: 0000000000000000
  dx: 0000000000000001  ax: 00002c43c8954588  cx: 0000000000000086  sp: 00007fff7d44d3e8
  ip: 00005624d813e5a5 efl: 0000000000010287 cgf: 002b000000000033 erf: 0000000000000004
 trp: 000000000000000e msk: 0000000000000000 cr2: 0000000000000020
[end of stack trace]
Comment 4 Ian Powell 2016-08-31 06:49:07 UTC
I've found an easy way to reproduce on my system.  zoom in and out on wwww.openstreetmap.org

Up to date tumbleweed "20160828"

chromium-52.0.2743.116-1.1.x86_64
Comment 5 Jon Brightwell 2016-08-31 08:00:34 UTC
*** Bug 996061 has been marked as a duplicate of this bug. ***
Comment 6 Swamp Workflow Management 2016-09-06 19:08:43 UTC
openSUSE-SU-2016:2250-1: An update that fixes 20 vulnerabilities is now available.

Category: security (important)
Bug References: 995932,996032,99606,996648
CVE References: CVE-2016-5147,CVE-2016-5148,CVE-2016-5149,CVE-2016-5150,CVE-2016-5151,CVE-2016-5152,CVE-2016-5153,CVE-2016-5154,CVE-2016-5155,CVE-2016-5156,CVE-2016-5157,CVE-2016-5158,CVE-2016-5159,CVE-2016-5160,CVE-2016-5161,CVE-2016-5162,CVE-2016-5163,CVE-2016-5164,CVE-2016-5165,CVE-2016-5166
Sources used:
openSUSE Leap 42.1 (src):    chromium-53.0.2785.89-68.1
Comment 7 Swamp Workflow Management 2016-09-06 19:09:30 UTC
SUSE-SU-2016:2251-1: An update that fixes 20 vulnerabilities is now available.

Category: security (important)
Bug References: 995932,996032,99606,996648
CVE References: CVE-2016-5147,CVE-2016-5148,CVE-2016-5149,CVE-2016-5150,CVE-2016-5151,CVE-2016-5152,CVE-2016-5153,CVE-2016-5154,CVE-2016-5155,CVE-2016-5156,CVE-2016-5157,CVE-2016-5158,CVE-2016-5159,CVE-2016-5160,CVE-2016-5161,CVE-2016-5162,CVE-2016-5163,CVE-2016-5164,CVE-2016-5165,CVE-2016-5166
Sources used:
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    chromium-53.0.2785.89-96.1
Comment 8 Bernhard Wiedemann 2016-09-10 10:00:36 UTC
This is an autogenerated message for OBS integration:
This bug (996032) was mentioned in
https://build.opensuse.org/request/show/426305 13.2 / chromium
Comment 9 Tomáš Chvátal 2016-09-10 11:04:02 UTC
This is fixed by chromium-53 thus closing.
Comment 10 Swamp Workflow Management 2016-09-13 11:09:48 UTC
openSUSE-SU-2016:2296-1: An update that fixes 20 vulnerabilities is now available.

Category: security (important)
Bug References: 969732,995932,996032,99606,996648,998328
CVE References: CVE-2016-5147,CVE-2016-5148,CVE-2016-5149,CVE-2016-5150,CVE-2016-5151,CVE-2016-5152,CVE-2016-5153,CVE-2016-5154,CVE-2016-5155,CVE-2016-5156,CVE-2016-5157,CVE-2016-5158,CVE-2016-5159,CVE-2016-5160,CVE-2016-5161,CVE-2016-5162,CVE-2016-5163,CVE-2016-5164,CVE-2016-5165,CVE-2016-5166
Sources used:
openSUSE 13.2 (src):    chromium-53.0.2785.101-120.1, rpmlint-1.5-39.4.1, rpmlint-mini-1.5-8.7.2