Bug 1591638 - WebKitWebProcess crashes when a11y is active
Summary: WebKitWebProcess crashes when a11y is active
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: webkitgtk4
Version: 7.6
Hardware: x86_64
OS: Linux
Target Milestone: rc
: ---
Assignee: Tomas Popela
QA Contact: Desktop QE
Depends On:
TreeView+ depends on / blocked
Reported: 2018-06-15 07:35 UTC by Michal Odehnal
Modified: 2019-01-04 07:48 UTC (History)
2 users (show)

Fixed In Version: webkitgtk4-2.20.4-1.el7
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Last Closed: 2018-10-30 10:28:48 UTC
Target Upstream Version:

Attachments (Terms of Use)
backtrace (19.18 KB, text/plain)
2018-06-15 11:22 UTC, Michal Odehnal
no flags Details

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:3140 0 None None None 2018-10-30 10:29:23 UTC
WebKit Project 187948 0 None None None 2019-01-04 07:48:40 UTC

Description Michal Odehnal 2018-06-15 07:35:24 UTC
Description of problem:
While trying to load some pages (pages tried: amazon.com, cnn.com and nytimes.com) MiniBrowser went blank after some elements loaded.

Journalctl log:
Jun 15 09:28:15 localhost.localdomain kernel: WebKitWebProces[12069]: segfault at bbadbeef ip 00007f26056673bc sp 00007ffce7c76ac0 error 6 in libjavascriptcoregtk-4.0.so.18.7.11[7f260484f000+1077000]
Jun 15 09:28:15 localhost.localdomain abrt-hook-ccpp[12555]: Process 12069 (WebKitWebProcess) of user 1000 killed by SIGSEGV - dumping core
Jun 15 09:28:18 localhost.localdomain abrt-server[12556]: Package 'webkitgtk4' isn't signed with proper key
Jun 15 09:28:18 localhost.localdomain abrt-server[12556]: 'post-create' on '/var/spool/abrt/ccpp-2018-06-15-09:28:15-12069' exited with 1
Jun 15 09:28:18 localhost.localdomain abrt-server[12556]: Deleting problem directory '/var/spool/abrt/ccpp-2018-06-15-09:28:15-12069'

Terminal messages:
1   0x7fac1262c3b7 /lib64/libjavascriptcoregtk-4.0.so.18(WTFCrash+0x17) [0x7fac1262c3b7]
2   0x7fac14a2fa75 /lib64/libwebkit2gtk-4.0.so.37(+0x1222a75) [0x7fac14a2fa75]
3   0x7fac14a2feb2 /lib64/libwebkit2gtk-4.0.so.37(+0x1222eb2) [0x7fac14a2feb2]
4   0x7fac14804ba2 /lib64/libwebkit2gtk-4.0.so.37(+0xff7ba2) [0x7fac14804ba2]
5   0x7fac1482fd61 /lib64/libwebkit2gtk-4.0.so.37(+0x1022d61) [0x7fac1482fd61]
6   0x7fac022dd33b /lib64/libatk-bridge-2.0.so.0(+0x1033b) [0x7fac022dd33b]
7   0x7fac0b9c9b27 /lib64/libgobject-2.0.so.0(+0x21b27) [0x7fac0b9c9b27]
8   0x7fac0b9d1ff1 /lib64/libgobject-2.0.so.0(g_signal_emit_valist+0xe11) [0x7fac0b9d1ff1]
9   0x7fac0b9d2828 /lib64/libgobject-2.0.so.0(g_signal_emit_by_name+0x528) [0x7fac0b9d2828]
10  0x7fac1482971a /lib64/libwebkit2gtk-4.0.so.37(+0x101c71a) [0x7fac1482971a]
11  0x7fac147e12ed /lib64/libwebkit2gtk-4.0.so.37(+0xfd42ed) [0x7fac147e12ed]
12  0x7fac15197ce1 /lib64/libwebkit2gtk-4.0.so.37(+0x198ace1) [0x7fac15197ce1]
13  0x7fac150ec5ac /lib64/libwebkit2gtk-4.0.so.37(+0x18df5ac) [0x7fac150ec5ac]
14  0x7fac1515841f /lib64/libwebkit2gtk-4.0.so.37(+0x194b41f) [0x7fac1515841f]
15  0x7fac1518e6b0 /lib64/libwebkit2gtk-4.0.so.37(+0x19816b0) [0x7fac1518e6b0]
16  0x7fac152ba191 /lib64/libwebkit2gtk-4.0.so.37(+0x1aad191) [0x7fac152ba191]
17  0x7fac152ba30e /lib64/libwebkit2gtk-4.0.so.37(+0x1aad30e) [0x7fac152ba30e]
18  0x7fac152c3ac7 /lib64/libwebkit2gtk-4.0.so.37(+0x1ab6ac7) [0x7fac152c3ac7]
19  0x7fac152c4005 /lib64/libwebkit2gtk-4.0.so.37(+0x1ab7005) [0x7fac152c4005]
20  0x7fac14a06b28 /lib64/libwebkit2gtk-4.0.so.37(+0x11f9b28) [0x7fac14a06b28]
21  0x7fac14a0b99f /lib64/libwebkit2gtk-4.0.so.37(+0x11fe99f) [0x7fac14a0b99f]
22  0x7fac14a0c00c /lib64/libwebkit2gtk-4.0.so.37(+0x11ff00c) [0x7fac14a0c00c]
23  0x7fac14a0c746 /lib64/libwebkit2gtk-4.0.so.37(+0x11ff746) [0x7fac14a0c746]
24  0x7fac14a0cb9e /lib64/libwebkit2gtk-4.0.so.37(+0x11ffb9e) [0x7fac14a0cb9e]
25  0x7fac14a8cfe5 /lib64/libwebkit2gtk-4.0.so.37(+0x127ffe5) [0x7fac14a8cfe5]
26  0x7fac14477bbb /lib64/libwebkit2gtk-4.0.so.37(+0xc6abbb) [0x7fac14477bbb]
27  0x7faba7fff185 [0x7faba7fff185]

Version-Release number of selected component (if applicable):

How reproducible:
Always on my machine

Steps to Reproduce:
1. /usr/libexec/webkit2gtk-4.0/MiniBrowser https://amazon.com
2. Wait until page loads.
3. Repeat step 1

Actual results:
Page is not loaded.

Expected results:
Page loads, no segfault.

Additional info:
Sometime before these crashes I see "failed to create drawable" message, not sure if its relevant.

Setting component to webkitgtk4, I am sure its not the cause by, please set correct component. If I can provide any other info, let me know.

Comment 2 Tomas Popela 2018-06-15 07:45:52 UTC
Please install the debuginfo packages and provide better backtrace. Can you also please provide more info about "failed to create drawable" message? Everything works fine here (F28 and the same version). Looks like some problems with system libraries.

Comment 3 Michal Odehnal 2018-06-15 10:57:15 UTC
I have tried clean install in our CI and result was the same as bug describes. I was unable to get better backtrace myself as I am missing some required debuginfo packages (as gdb suggests: libblkid libcom_err libmount libuuid) and I was not able to find them. Backtrace was too big to attach so here is a link: http://file01.intranet.prod.int.rdu2.redhat.com/~modehnal/webkitcrash.tar.gz

If you require more information, I can provide VM where the bug can be reproduced.

Comment 4 Michal Odehnal 2018-06-15 11:22:59 UTC
Created attachment 1451890 [details]

Comment 5 Tomas Popela 2018-07-17 13:22:04 UTC
Only reproducible when running tests with behave.

Comment 7 Michal Odehnal 2018-08-28 06:44:35 UTC
Cant reproduce with webkitgtk4-2.20.5-1.el7.x86_64. Moving to verified.

Comment 9 errata-xmlrpc 2018-10-30 10:28:48 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.