unexpected signal delivery when replaying Firefox crashtest recording
Open
Nobody has claimed this yet.
- Dominant language
- C++
- Stars
- 10.7k
- Forks
- 662
- Avg merge
- 2d 3h
- Merged PRs (30d)
- 2
Description
$ ./mach crashtest layout/base/crashtests/ --filter 374193-1.xhtml --debugger=rr --debugger-args=-M
... (crashtest runs and exists after a fatal assertion, with some patches applied) ...
$ rr replay
...
(gdb) c
...
[FATAL /z/rr/rr/src/ReplaySession.cc:560:guard_unexpected_signal() errno: 0 'Success']
(task 19000 (rec:18881) at time 8064)
-> Assertion `child_sig_is_zero_or_sigtrap' failed to hold. Replay got unrecorded event SIGNAL: SIGSEGV(async) while awaiting signal
Log around time 8064:
{
global_time:8056, event:`SYSCALL: munmap' (state:ENTERING_SYSCALL) tid:18879, ticks:8770267 rax:0xffffffffffffffda rbx:0xb rcx:0xffffffffffffffff rdx:0x2 rsi:0x2c13c80 rdi:0x2b7c1c72b000 rbp:0x7fff41268b80 rsp:0x7fff41268500 r8:0x0 r9:0xca r10:0x2b7c1f2a8e80 r11:0x202 r12:0x2b7c08d99800 r13:0x4f r14:0x0 r15:0x7fff41268620 rip:0 x70000018 eflags:0x202 cs:0x33 ss:0x2b ds:0x0 es:0x0 fs:0x0 gs:0x0 orig_rax:0xb
}
{
global_time:8057, event:`SYSCALL: munmap' (state:EXITING_SYSCALL) tid:18879, ticks:8770267 rax:0x0 rbx:0xb rcx:0xffffffffffffffff rdx:0x2 rsi:0x2c13c80 rdi:0x2b7c1c72b000 rbp:0x7fff41268b80 rsp:0x7fff41268500 r8:0x0 r9:0xca r10:0x2b7c1f2a8e80 r11:0x202 r12:0x2b7c08d99800 r13:0x4f r14:0x0 r15:0x7fff41268620 rip:0x70000018 eflags:0x202 cs:0x33 ss:0x2b ds:0x0 es:0x0 fs:0x0 gs:0x0 orig_rax:0xb
}
{
global_time:8058, event:`PATCH_SYSCALL' tid:18879, ticks:8770630
}
{
global_time:8059, event:`SYSCALLBUF_FLUSH' tid:18879, ticks:8770922
}
{
global_time:8060, event:`PATCH_SYSCALL' tid:18879, ticks:8770922
}
{
global_time:8061, event:`SYSCALLBUF_RESET' tid:18879, ticks:8770922
}
{
global_time:8062, event:`SYSCALL: exit_group' (state:ENTERING_SYSCALL) tid:18879, ticks:8770923 rax:0xffffffffffffffda rbx:0xe7 rcx:0xffffffffffffffff rdx:0x0 rsi:0x7fff41268d50 rdi:0x0 rbp:0x7fff412692b0 rsp:0x7fff41269020 r8:0x3c r9:0xe7 r10:0xffffffffffffff20 r11:0x202 r12:0x2b7c11e4d8fc r13:0x7fff4126a980 r14:0x0 r15:0x7fff41269140 rip:0x70000018 eflags:0x202 cs:0x33 ss:0x2b ds:0x0 es:0x0 fs:0x0 gs:0x0 orig_rax:0xe7
}
{
global_time:8063, event:`EXIT' tid:18879, ticks:8770923
}
{
global_time:8064, event:`SIGNAL: SIGCHLD(async)' tid:18881, ticks:0 rax:0x0 rbx:0x2b7c1d50c700 rcx:0xffffffffffffffff rdx:0x2b7c1d50c9d0 rsi:0x2b7c1d50bf70 rdi:0x3d0f00 rbp:0x7fff41269100 rsp:0x2b7c1d50bf70 r8:0x2b7c1d50c700 r9:0x2b7c1d50c700 r10:0x2b7c1d50c9d0 r11:0x202 r12:0x0 r13:0x0 r14:0x2b7c1d50c9c0 r15:0x2b7c1d50c700 rip:0x2b7c08884441 eflags:0x202 cs:0x33 ss:0x2b ds:0x0 es:0x0 fs:0x0 gs:0x0 orig_rax:0x38
}
{
global_time:8065, event:`SIGNAL_DELIVERY: SIGCHLD(async)' tid:18881, ticks:0 rax:0x0 rbx:0x2b7c1d50c700 rcx:0xffffffffffffffff rdx:0x2b7c1d50c9d0 rsi:0x2b7c1d50bf70 rdi:0x3d0f00 rbp:0x7fff41269100 rsp:0x2b7c1d50bf70 r8:0x2b7c1d50c700 r9:0x2b7c1d50c700 r10:0x2b7c1d50c9d0 r11:0x202 r12:0x0 r13:0x0 r14:0x2b7c1d50c9c0 r15:0x2b7c1d50c700 rip:0x2b7c08884441 eflags:0x202 cs:0x33 ss:0x2b ds:0x0 es:0x0 fs:0x0 gs:0x0 orig_rax:0x38
}
{
global_time:8066, event:`SEGV_RDTSC' tid:18881, ticks:3 rax:0xdc4a5aae rbx:0x2b7c1d50c700 rcx:0xffffffffffffffff rdx:0x8e7bf rsi:0x2b7c1d50bf70 rdi:0x2b7c1d50c700 rbp:0x0 rsp:0x2b7c1d50bee0 r8:0x2b7c1d50c700 r9:0x2b7c1d50c700 r10:0x2b7c1d50c9d0 r11:0x202 r12:0x0 r13:0x0 r14:0x2b7c1d50c9c0 r15:0x2b7c1d50c700 rip:0x2b7c07b500d2 eflags:0x10202 cs:0x33 ss:0x2b ds:0x0 es:0x0 fs:0x0 gs:0x0 orig_rax:0xffffffffffffffff
}
When I record with -n the replay runs fine.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the failure in rr/src/ReplaySession.cc around guard_unexpected_signal() and reproduce using the ./mach crashtest command, --debugger=rr, and rr replay. Compare this recording with the -n recording that replays successfully, focusing on the SIGCHLD and subsequent signal events around global time 8064. Done means the recording no longer aborts with the unexpected-signal assertion.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- cpp, linux
- Domain
- devtools, operating-systems, reverse-engineering
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100