Bug 1591638

Summary: WebKitWebProcess crashes when a11y is active
Product: Red Hat Enterprise Linux 7 Reporter: Michal Odehnal <modehnal>
Component: webkitgtk4Assignee: Tomas Popela <tpopela>
Status: CLOSED ERRATA QA Contact: Desktop QE <desktop-qa-list>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 7.6CC: modehnal, tpelka
Target Milestone: rc   
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: webkitgtk4-2.20.4-1.el7 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-10-30 10:28:48 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
backtrace none

Description Michal Odehnal 2018-06-15 07:35:24 UTC
Description of problem:
While trying to load some pages (pages tried: amazon.com, cnn.com and nytimes.com) MiniBrowser went blank after some elements loaded.

Journalctl log:
Jun 15 09:28:15 localhost.localdomain kernel: WebKitWebProces[12069]: segfault at bbadbeef ip 00007f26056673bc sp 00007ffce7c76ac0 error 6 in libjavascriptcoregtk-4.0.so.18.7.11[7f260484f000+1077000]
Jun 15 09:28:15 localhost.localdomain abrt-hook-ccpp[12555]: Process 12069 (WebKitWebProcess) of user 1000 killed by SIGSEGV - dumping core
Jun 15 09:28:18 localhost.localdomain abrt-server[12556]: Package 'webkitgtk4' isn't signed with proper key
Jun 15 09:28:18 localhost.localdomain abrt-server[12556]: 'post-create' on '/var/spool/abrt/ccpp-2018-06-15-09:28:15-12069' exited with 1
Jun 15 09:28:18 localhost.localdomain abrt-server[12556]: Deleting problem directory '/var/spool/abrt/ccpp-2018-06-15-09:28:15-12069'

Terminal messages:
1   0x7fac1262c3b7 /lib64/libjavascriptcoregtk-4.0.so.18(WTFCrash+0x17) [0x7fac1262c3b7]
2   0x7fac14a2fa75 /lib64/libwebkit2gtk-4.0.so.37(+0x1222a75) [0x7fac14a2fa75]
3   0x7fac14a2feb2 /lib64/libwebkit2gtk-4.0.so.37(+0x1222eb2) [0x7fac14a2feb2]
4   0x7fac14804ba2 /lib64/libwebkit2gtk-4.0.so.37(+0xff7ba2) [0x7fac14804ba2]
5   0x7fac1482fd61 /lib64/libwebkit2gtk-4.0.so.37(+0x1022d61) [0x7fac1482fd61]
6   0x7fac022dd33b /lib64/libatk-bridge-2.0.so.0(+0x1033b) [0x7fac022dd33b]
7   0x7fac0b9c9b27 /lib64/libgobject-2.0.so.0(+0x21b27) [0x7fac0b9c9b27]
8   0x7fac0b9d1ff1 /lib64/libgobject-2.0.so.0(g_signal_emit_valist+0xe11) [0x7fac0b9d1ff1]
9   0x7fac0b9d2828 /lib64/libgobject-2.0.so.0(g_signal_emit_by_name+0x528) [0x7fac0b9d2828]
10  0x7fac1482971a /lib64/libwebkit2gtk-4.0.so.37(+0x101c71a) [0x7fac1482971a]
11  0x7fac147e12ed /lib64/libwebkit2gtk-4.0.so.37(+0xfd42ed) [0x7fac147e12ed]
12  0x7fac15197ce1 /lib64/libwebkit2gtk-4.0.so.37(+0x198ace1) [0x7fac15197ce1]
13  0x7fac150ec5ac /lib64/libwebkit2gtk-4.0.so.37(+0x18df5ac) [0x7fac150ec5ac]
14  0x7fac1515841f /lib64/libwebkit2gtk-4.0.so.37(+0x194b41f) [0x7fac1515841f]
15  0x7fac1518e6b0 /lib64/libwebkit2gtk-4.0.so.37(+0x19816b0) [0x7fac1518e6b0]
16  0x7fac152ba191 /lib64/libwebkit2gtk-4.0.so.37(+0x1aad191) [0x7fac152ba191]
17  0x7fac152ba30e /lib64/libwebkit2gtk-4.0.so.37(+0x1aad30e) [0x7fac152ba30e]
18  0x7fac152c3ac7 /lib64/libwebkit2gtk-4.0.so.37(+0x1ab6ac7) [0x7fac152c3ac7]
19  0x7fac152c4005 /lib64/libwebkit2gtk-4.0.so.37(+0x1ab7005) [0x7fac152c4005]
20  0x7fac14a06b28 /lib64/libwebkit2gtk-4.0.so.37(+0x11f9b28) [0x7fac14a06b28]
21  0x7fac14a0b99f /lib64/libwebkit2gtk-4.0.so.37(+0x11fe99f) [0x7fac14a0b99f]
22  0x7fac14a0c00c /lib64/libwebkit2gtk-4.0.so.37(+0x11ff00c) [0x7fac14a0c00c]
23  0x7fac14a0c746 /lib64/libwebkit2gtk-4.0.so.37(+0x11ff746) [0x7fac14a0c746]
24  0x7fac14a0cb9e /lib64/libwebkit2gtk-4.0.so.37(+0x11ffb9e) [0x7fac14a0cb9e]
25  0x7fac14a8cfe5 /lib64/libwebkit2gtk-4.0.so.37(+0x127ffe5) [0x7fac14a8cfe5]
26  0x7fac14477bbb /lib64/libwebkit2gtk-4.0.so.37(+0xc6abbb) [0x7fac14477bbb]
27  0x7faba7fff185 [0x7faba7fff185]


Version-Release number of selected component (if applicable):
webkitgtk4-2.20.3-3.el7.x86_64

How reproducible:
Always on my machine

Steps to Reproduce:
1. /usr/libexec/webkit2gtk-4.0/MiniBrowser https://amazon.com
2. Wait until page loads.
3. Repeat step 1

Actual results:
Page is not loaded.

Expected results:
Page loads, no segfault.

Additional info:
Sometime before these crashes I see "failed to create drawable" message, not sure if its relevant.

Setting component to webkitgtk4, I am sure its not the cause by, please set correct component. If I can provide any other info, let me know.

Comment 2 Tomas Popela 2018-06-15 07:45:52 UTC
Please install the debuginfo packages and provide better backtrace. Can you also please provide more info about "failed to create drawable" message? Everything works fine here (F28 and the same version). Looks like some problems with system libraries.

Comment 3 Michal Odehnal 2018-06-15 10:57:15 UTC
I have tried clean install in our CI and result was the same as bug describes. I was unable to get better backtrace myself as I am missing some required debuginfo packages (as gdb suggests: libblkid libcom_err libmount libuuid) and I was not able to find them. Backtrace was too big to attach so here is a link: http://file01.intranet.prod.int.rdu2.redhat.com/~modehnal/webkitcrash.tar.gz

If you require more information, I can provide VM where the bug can be reproduced.

Comment 4 Michal Odehnal 2018-06-15 11:22:59 UTC
Created attachment 1451890 [details]
backtrace

Comment 5 Tomas Popela 2018-07-17 13:22:04 UTC
Only reproducible when running tests with behave.

Comment 7 Michal Odehnal 2018-08-28 06:44:35 UTC
Cant reproduce with webkitgtk4-2.20.5-1.el7.x86_64. Moving to verified.

Comment 9 errata-xmlrpc 2018-10-30 10:28:48 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2018:3140