<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>194094</bug_id>
          
          <creation_ts>2019-01-31 09:49:18 -0800</creation_ts>
          <short_desc>Regression(PSON) Crash under WebProcessProxy::canTerminateChildProcess()</short_desc>
          <delta_ts>2019-01-31 16:01:07 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebKit2</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Chris Dumez">cdumez</reporter>
          <assigned_to name="Chris Dumez">cdumez</assigned_to>
          <cc>achristensen</cc>
    
    <cc>beidson</cc>
    
    <cc>commit-queue</cc>
    
    <cc>ggaren</cc>
    
    <cc>jiewen_tan</cc>
    
    <cc>rniwa</cc>
    
    <cc>ryanhaddad</cc>
    
    <cc>tsavell</cc>
    
    <cc>webkit-bug-importer</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1500614</commentid>
    <comment_count>0</comment_count>
    <who name="Chris Dumez">cdumez</who>
    <bug_when>2019-01-31 09:49:18 -0800</bug_when>
    <thetext>Crash under WebProcessProxy::canTerminateChildProcess():
Exception Type:  EXC_BAD_ACCESS (SIGSEGV)
Exception Subtype: KERN_INVALID_ADDRESS at 0x0000000000000018
VM Region Info: 0x18 is not in any region.  Bytes before following region: 4309712872
      REGION TYPE                      START - END             [ VSIZE] PRT/MAX SHRMOD  REGION DETAIL
      UNUSED SPACE AT START
---&gt;  
      __TEXT                 0000000100e10000-0000000100fe8000 [ 1888K] r-x/r-x SM=COW  .../MobileSafari

Termination Signal: Segmentation fault: 11
Termination Reason: Namespace SIGNAL, Code 0xb
Terminating Process: exc handler [597]
Triggered by Thread:  0

Thread 0 name:  Dispatch queue: com.apple.main-thread
Thread 0 Crashed:
0   WebKit                        	0x00000001f1328c20 WebKit::WebProcessProxy::canTerminateChildProcess() + 48 (DumbPtrTraits.h:41)
1   WebKit                        	0x00000001f1327128 WebKit::WebProcessProxy::maybeShutDown() + 36 (WebProcessProxy.cpp:868)
2   WebKit                        	0x00000001f1327084 WebKit::WebProcessProxy::removeWebPage(WebKit::WebPageProxy&amp;, unsigned long long, WebKit::WebProcessProxy::EndsUsingDataStore) + 124 (WebProcessProxy.cpp:473)
3   WebKit                        	0x00000001f12f5d00 WebKit::WebPageProxy::continueNavigationInNewProcess(API::Navigation&amp;, std::__1::unique_ptr&lt;WebKit::SuspendedPageProxy, std::__1::default_delete&lt;WebKit::SuspendedPageProxy&gt; &gt;&amp;&amp;, WTF::Ref&lt;WebKit::WebProcessProxy, WTF::DumbPtrTraits&lt;WebKit::WebProcessProxy&gt; &gt;&amp;&amp;, WebKit::ProcessSwapRequestedByClient, WTF::Optional&lt;WebKit::WebsitePoliciesData&gt;&amp;&amp;) + 420 (WebPageProxy.cpp:2760)
4   WebKit                        	0x00000001f130d4f4 WTF::Function&lt;void (WTF::Ref&lt;WebKit::WebProcessProxy, WTF::DumbPtrTraits&lt;WebKit::WebProcessProxy&gt; &gt;&amp;&amp;, WebKit::SuspendedPageProxy*, WTF::String const&amp;)&gt;::CallableWrapper&lt;WebKit::WebPageProxy::receivedNavigationPolicyDecision(WebKit::WebPolicyAction, API::Navigation*, WebKit::ProcessSwapRequestedByClient, WebKit::WebFrameProxy&amp;, API::WebsitePolicies*, WTF::Ref&lt;WebKit::WebPageProxy::PolicyDecisionSender, WTF::DumbPtrTraits&lt;WebKit::WebPageProxy::PolicyDecisionSender&gt; &gt;&amp;&amp;)::$_5&gt;::call(WTF::Ref&lt;WebKit::WebProcessProxy, WTF::DumbPtrTraits&lt;WebKit::WebProcessProxy&gt; &gt;&amp;&amp;, WebKit::SuspendedPageProxy*, WTF::String const&amp;) + 816 (WebPageProxy.cpp:2709)
5   WebKit                        	0x00000001f1332e08 WTF::Function&lt;void (WTF::Ref&lt;WebKit::WebProcessProxy, WTF::DumbPtrTraits&lt;WebKit::WebProcessProxy&gt; &gt;&amp;&amp;, WebKit::SuspendedPageProxy*, WTF::String const&amp;)&gt;::CallableWrapper&lt;WebKit::WebProcessPool::processForNavigation(WebKit::WebPageProxy&amp;, API::Navigation const&amp;, WebKit::ProcessSwapRequestedByClient, WTF::CompletionHandler&lt;void (WTF::Ref&lt;WebKit::WebProcessProxy, WTF::DumbPtrTraits&lt;WebKit::WebProcessProxy&gt; &gt;&amp;&amp;, WebKit::SuspendedPageProxy*, WTF::String const&amp;)&gt;&amp;&amp;)::$_14&gt;::call(WTF::Ref&lt;WebKit::WebProcessProxy, WTF::DumbPtrTraits&lt;WebKit::WebProcessProxy&gt; &gt;&amp;&amp;, WebKit::SuspendedPageProxy*, WTF::String const&amp;) + 196 (Function.h:56)
6   WebKit                        	0x00000001f13330c0 WTF::Function&lt;void (WebKit::SuspendedPageProxy*)&gt;::CallableWrapper&lt;WebKit::WebProcessPool::processForNavigationInternal(WebKit::WebPageProxy&amp;, API::Navigation const&amp;, WebKit::ProcessSwapRequestedByClient, WTF::CompletionHandler&lt;void (WTF::Ref&lt;WebKit::WebProcessProxy, WTF::DumbPtrTraits&lt;WebKit::WebProcessProxy&gt; &gt;&amp;&amp;, WebKit::SuspendedPageProxy*, WTF::String const&amp;)&gt;&amp;&amp;)::$_15&gt;::call(WebKit::SuspendedPageProxy*) + 348 (Function.h:56)
7   WebKit                        	0x00000001f12bfa54 WebKit::SuspendedPageProxy::~SuspendedPageProxy() + 72 (Function.h:56)
8   WebKit                        	0x00000001f12bfc4c WebKit::SuspendedPageProxy::~SuspendedPageProxy() + 12 (SuspendedPageProxy.cpp:93)
9   WebKit                        	0x00000001f132ee78 WTF::Deque&lt;std::__1::unique_ptr&lt;WebKit::SuspendedPageProxy, std::__1::default_delete&lt;WebKit::SuspendedPageProxy&gt; &gt;, 0ul&gt;::destroyAll() + 192 (memory:2321)
10  WebKit                        	0x00000001f1320d0c WTF::Deque&lt;std::__1::unique_ptr&lt;WebKit::SuspendedPageProxy, std::__1::default_delete&lt;WebKit::SuspendedPageProxy&gt; &gt;, 0ul&gt;::clear() + 20 (Deque.h:389)
11  WebKit                        	0x00000001f12cb0f0 WTF::Function&lt;void (WTF::Critical, WTF::Synchronous)&gt;::CallableWrapper&lt;WebKit::installMemoryPressureHandler()::$_0&gt;::call(WTF::Critical, WTF::Synchronous) + 60 (WebMemoryPressureHandlerCocoa.mm:49)
12  JavaScriptCore                	0x00000001e8dbdca8 WTF::MemoryPressureHandler::releaseMemory(WTF::Critical, WTF::Synchronous) + 92 (Function.h:56)
13  JavaScriptCore                	0x00000001e8dbe3bc invocation function for block in WTF::MemoryPressureHandler::install() + 140 (MemoryPressureHandlerCocoa.mm:192)
14  libdispatch.dylib             	0x00000001e0e457d4 _dispatch_client_callout + 16 (object.m:511)
15  libdispatch.dylib             	0x00000001e0dea018 _dispatch_continuation_pop$VARIANT$mp + 412 (inline_internal.h:2441)
16  libdispatch.dylib             	0x00000001e0df9fa4 _dispatch_source_invoke$VARIANT$mp + 1308 (source.c:568)
17  libdispatch.dylib             	0x00000001e0df2ee8 _dispatch_main_queue_callback_4CF$VARIANT$mp + 784 (inline_internal.h:2482)
18  CoreFoundation                	0x00000001e1391e7c __CFRUNLOOP_IS_SERVICING_THE_MAIN_DISPATCH_QUEUE__ + 12 (CFRunLoop.c:1813)
19  CoreFoundation                	0x00000001e138cdb0 __CFRunLoopRun + 1940 (CFRunLoop.c:3113)
20  CoreFoundation                	0x00000001e138c2fc CFRunLoopRunSpecific + 436 (CFRunLoop.c:3247)
21  GraphicsServices              	0x00000001e358d79c GSEventRunModal + 104 (GSEvent.c:2245)
22  UIKitCore                     	0x000000020ddf3558 UIApplicationMain + 212 (UIApplication.m:4353)
23  MobileSafari                  	0x0000000100e155a0 main + 1500 (main.m:121)
24  libdyld.dylib                 	0x00000001e0e55b80 start + 4</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1500615</commentid>
    <comment_count>1</comment_count>
    <who name="Chris Dumez">cdumez</who>
    <bug_when>2019-01-31 09:49:32 -0800</bug_when>
    <thetext>&lt;rdar://problem/47580753&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1500617</commentid>
    <comment_count>2</comment_count>
      <attachid>360736</attachid>
    <who name="Chris Dumez">cdumez</who>
    <bug_when>2019-01-31 09:56:17 -0800</bug_when>
    <thetext>Created attachment 360736
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1500679</commentid>
    <comment_count>3</comment_count>
      <attachid>360736</attachid>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2019-01-31 11:49:50 -0800</bug_when>
    <thetext>Comment on attachment 360736
Patch

Clearing flags on attachment: 360736

Committed r240803: &lt;https://trac.webkit.org/changeset/240803&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1500680</commentid>
    <comment_count>4</comment_count>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2019-01-31 11:49:51 -0800</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1500846</commentid>
    <comment_count>5</comment_count>
    <who name="Chris Dumez">cdumez</who>
    <bug_when>2019-01-31 15:31:14 -0800</bug_when>
    <thetext>Reopening as this seems to have caused API test failures on iOS:
https://build.webkit.org/builders/Apple%20iOS%2012%20Simulator%20Release%20WK2%20%28Tests%29/builds/2336</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1500861</commentid>
    <comment_count>6</comment_count>
    <who name="Chris Dumez">cdumez</who>
    <bug_when>2019-01-31 15:50:53 -0800</bug_when>
    <thetext>(In reply to Chris Dumez from comment #5)
&gt; Reopening as this seems to have caused API test failures on iOS:
&gt; https://build.webkit.org/builders/
&gt; Apple%20iOS%2012%20Simulator%20Release%20WK2%20%28Tests%29/builds/2336

Actually, given the crashes, I strongly suspect this was caused by Jiewen&apos;s r240555:
Crashed

    TestWebKitAPI.ProcessSwap.CrossOriginSystemPreview
        Received data during response processing, queuing it.
        2019-01-31 15:44:39.513 TestWebKitAPI[84804:3453689] *** Terminating app due to uncaught exception &apos;NSInvalidArgumentException&apos;, reason: &apos;[NSXPCConnection sendInvocation]: Block was not compiled using a compiler that inserts type information about arguments. (openAppLink:state:completionHandler:)&apos;
        *** First throw call stack:
        (
        	0   CoreFoundation                      0x000000010b43cfb2 __exceptionPreprocess + 370
        	1   libobjc.A.dylib                     0x000000010b219ac5 objc_exception_throw + 48
        	2   Foundation                          0x000000010ae71954 -[NSXPCConnection _sendInvocation:orArguments:count:methodSignature:selector:withProxy:] + 4021
        	3   Foundation                          0x000000010ae70862 -[NSXPCConnection _sendSelector:withProxy:arg1:arg2:arg3:] + 133
        	4   Foundation                          0x000000010ae82b7e _NSXPCDistantObjectSimpleMessageSend3 + 57
        	5   CoreServices                        0x000000010b93be11 +[LSAppLink(Internal) _openWithAppLink:state:completionHandler:] + 279
        	6   CoreServices                        0x000000010b93aaf5 __66+[LSAppLink(QRCodes) openWithURL:configuration:completionHandler:]_block_invoke + 116
        	7   libdispatch.dylib                   0x000000010bc36ad0 _dispatch_call_block_and_release + 12
        	8   libdispatch.dylib                   0x000000010bc37c5e _dispatch_client_callout + 8
        	9   libdispatch.dylib                   0x000000010bc3e5fc _dispatch_lane_serial_drain + 672
        	10  libdispatch.dylib                   0x000000010bc3f0a0 _dispatch_lane_invoke + 444
        	11  libdispatch.dylib                   0x000000010bc494b7 _dispatch_workloop_worker_thread + 626
        	12  libsystem_pthread.dylib             0x000000010c03c60b _pthread_wqthread + 409
        	13  libsystem_pthread.dylib             0x000000010c03c405 start_wqthread + 13
        )
        libc++abi.dylib: terminating with uncaught exception of type NSException
        Child process terminated with signal 6: Abort trap


Unsure why Truitt accused me, Jiewen&apos;s patch is even the only patch in the range:
https://build.webkit.org/builders/Apple%20iOS%2012%20Simulator%20Release%20WK2%20%28Tests%29/builds/2336</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>360736</attachid>
            <date>2019-01-31 09:56:17 -0800</date>
            <delta_ts>2019-01-31 11:49:50 -0800</delta_ts>
            <desc>Patch</desc>
            <filename>bug-194094-20190131095616.patch</filename>
            <type>text/plain</type>
            <size>1907</size>
            <attacher name="Chris Dumez">cdumez</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogMjQwNzkzCmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViS2l0L0No
YW5nZUxvZyBiL1NvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCmluZGV4IGRkMDllMWJjZDc3YzEzOTA0
ZjBlZGVmNjUyNTNmMTE5Mzk1ZTBhMDUuLjk5ZTFmZWVkNGIxNWJhYTc5ZDg0YTI5Mjg2ZmM5ZGJl
MmZiMDAzMzkgMTAwNjQ0Ci0tLSBhL1NvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCisrKyBiL1NvdXJj
ZS9XZWJLaXQvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTggQEAKKzIwMTktMDEtMzEgIENocmlzIER1
bWV6ICA8Y2R1bWV6QGFwcGxlLmNvbT4KKworICAgICAgICBSZWdyZXNzaW9uKFBTT04pIENyYXNo
IHVuZGVyIFdlYlByb2Nlc3NQcm94eTo6Y2FuVGVybWluYXRlQ2hpbGRQcm9jZXNzKCkKKyAgICAg
ICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lkPTE5NDA5NAorICAgICAg
ICA8cmRhcjovL3Byb2JsZW0vNDc1ODA3NTM+CisKKyAgICAgICAgUmV2aWV3ZWQgYnkgTk9CT0RZ
IChPT1BTISkuCisKKyAgICAgICAgSWYgYSBTdXNwZW5kZWRQYWdlUHJveHkgZ2V0cyBkZXN0cm95
ZWQgd2hpbGUgYSBXZWJQYWdlUHJveHkgaXMgd2FpdGluZyBmb3IgaXRzIHRvIGZpbmlzaCB0byBz
dXNwZW5kLAorICAgICAgICBjYWxsIHRoZSAiZmFpbHVyZSB0byBzdXNwZW5kIiBjb21wbGV0aW9u
IGhhbmRsZXIgYXN5bmNocm9ub3VzbHkgaW5zdGVhZCBvZiBzeW5jaHJvbm91bHkgdG8gbWFrZSBz
dXJlCisgICAgICAgIHRoZSBjb21wbGV0aW9uIGhhbmRsZXIgY2Fubm90IHRyeSBhbmQgdXNlIHRo
ZSBzdXNwZW5kZWQgcGFnZSBwcm94eSB3aGlsZSBpdCBpcyBiZWluZyBkZXN0cm95ZWQuCisKKyAg
ICAgICAgKiBVSVByb2Nlc3MvU3VzcGVuZGVkUGFnZVByb3h5LmNwcDoKKyAgICAgICAgKFdlYktp
dDo6U3VzcGVuZGVkUGFnZVByb3h5Ojp+U3VzcGVuZGVkUGFnZVByb3h5KToKKwogMjAxOS0wMS0z
MCAgU2ltb24gRnJhc2VyICA8c2ltb24uZnJhc2VyQGFwcGxlLmNvbT4KIAogICAgICAgICBbTWFj
XSBJbXBsZW1lbnQgYmFzaWMgaGl0IHRlc3RpbmcgaW4gdGhlIHNjcm9sbGluZyB0cmVlCmRpZmYg
LS1naXQgYS9Tb3VyY2UvV2ViS2l0L1VJUHJvY2Vzcy9TdXNwZW5kZWRQYWdlUHJveHkuY3BwIGIv
U291cmNlL1dlYktpdC9VSVByb2Nlc3MvU3VzcGVuZGVkUGFnZVByb3h5LmNwcAppbmRleCAwNDk1
MDdlMTk2NDE3YjBmYmFmMjc1ZDZiMDNmYzFlN2JkNzI0NjNmLi4wYzk4MWYyOTc2Zjg2YjE3ZmVj
ZjliNDY1ZmI2NTdjMGNiMjA4YzBjIDEwMDY0NAotLS0gYS9Tb3VyY2UvV2ViS2l0L1VJUHJvY2Vz
cy9TdXNwZW5kZWRQYWdlUHJveHkuY3BwCisrKyBiL1NvdXJjZS9XZWJLaXQvVUlQcm9jZXNzL1N1
c3BlbmRlZFBhZ2VQcm94eS5jcHAKQEAgLTkyLDggKzkyLDExIEBAIFN1c3BlbmRlZFBhZ2VQcm94
eTo6U3VzcGVuZGVkUGFnZVByb3h5KFdlYlBhZ2VQcm94eSYgcGFnZSwgUmVmPFdlYlByb2Nlc3NQ
cm94eT4mCiAKIFN1c3BlbmRlZFBhZ2VQcm94eTo6flN1c3BlbmRlZFBhZ2VQcm94eSgpCiB7Ci0g
ICAgaWYgKG1fcmVhZHlUb1Vuc3VzcGVuZEhhbmRsZXIpCi0gICAgICAgIG1fcmVhZHlUb1Vuc3Vz
cGVuZEhhbmRsZXIobnVsbHB0cik7CisgICAgaWYgKG1fcmVhZHlUb1Vuc3VzcGVuZEhhbmRsZXIp
IHsKKyAgICAgICAgUnVuTG9vcDo6bWFpbigpLmRpc3BhdGNoKFtyZWFkeVRvVW5zdXNwZW5kSGFu
ZGxlciA9IFdURk1vdmUobV9yZWFkeVRvVW5zdXNwZW5kSGFuZGxlcildKCkgbXV0YWJsZSB7Cisg
ICAgICAgICAgICByZWFkeVRvVW5zdXNwZW5kSGFuZGxlcihudWxscHRyKTsKKyAgICAgICAgfSk7
CisgICAgfQogCiAgICAgaWYgKG1fc3VzcGVuc2lvblN0YXRlID09IFN1c3BlbnNpb25TdGF0ZTo6
UmVzdW1lZCkKICAgICAgICAgcmV0dXJuOwo=
</data>

          </attachment>
      

    </bug>

</bugzilla>