rr-debugger / rr-debugger/rr

unexpected signal delivery when replaying Firefox crashtest recording

Open
#1,539 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
C++
Stars
10.7k
Forks
662
Avg merge
2d 3h
Merged PRs (30d)
2

Description

$ ./mach crashtest layout/base/crashtests/ --filter 374193-1.xhtml --debugger=rr --debugger-args=-M
... (crashtest runs and exists after a fatal assertion, with some patches applied) ...
$ rr replay
...
(gdb) c
...
[FATAL /z/rr/rr/src/ReplaySession.cc:560:guard_unexpected_signal() errno: 0 'Success'] 
 (task 19000 (rec:18881) at time 8064)
 ->  Assertion `child_sig_is_zero_or_sigtrap' failed to hold. Replay got unrecorded event SIGNAL: SIGSEGV(async) while awaiting signal

Log around time 8064:

{
  global_time:8056, event:`SYSCALL: munmap' (state:ENTERING_SYSCALL) tid:18879, ticks:8770267 rax:0xffffffffffffffda rbx:0xb rcx:0xffffffffffffffff rdx:0x2 rsi:0x2c13c80 rdi:0x2b7c1c72b000 rbp:0x7fff41268b80 rsp:0x7fff41268500 r8:0x0 r9:0xca r10:0x2b7c1f2a8e80 r11:0x202 r12:0x2b7c08d99800 r13:0x4f r14:0x0 r15:0x7fff41268620 rip:0 x70000018 eflags:0x202 cs:0x33 ss:0x2b ds:0x0 es:0x0 fs:0x0 gs:0x0 orig_rax:0xb
}
{
  global_time:8057, event:`SYSCALL: munmap' (state:EXITING_SYSCALL) tid:18879, ticks:8770267 rax:0x0 rbx:0xb rcx:0xffffffffffffffff rdx:0x2 rsi:0x2c13c80 rdi:0x2b7c1c72b000 rbp:0x7fff41268b80 rsp:0x7fff41268500 r8:0x0 r9:0xca r10:0x2b7c1f2a8e80 r11:0x202 r12:0x2b7c08d99800 r13:0x4f r14:0x0 r15:0x7fff41268620 rip:0x70000018 eflags:0x202 cs:0x33 ss:0x2b ds:0x0 es:0x0 fs:0x0 gs:0x0 orig_rax:0xb
}
{
  global_time:8058, event:`PATCH_SYSCALL' tid:18879, ticks:8770630
}
{
  global_time:8059, event:`SYSCALLBUF_FLUSH' tid:18879, ticks:8770922
}
{
  global_time:8060, event:`PATCH_SYSCALL' tid:18879, ticks:8770922
}
{
  global_time:8061, event:`SYSCALLBUF_RESET' tid:18879, ticks:8770922
}
{
  global_time:8062, event:`SYSCALL: exit_group' (state:ENTERING_SYSCALL) tid:18879, ticks:8770923 rax:0xffffffffffffffda rbx:0xe7 rcx:0xffffffffffffffff rdx:0x0 rsi:0x7fff41268d50 rdi:0x0 rbp:0x7fff412692b0 rsp:0x7fff41269020 r8:0x3c r9:0xe7 r10:0xffffffffffffff20 r11:0x202 r12:0x2b7c11e4d8fc r13:0x7fff4126a980 r14:0x0 r15:0x7fff41269140 rip:0x70000018 eflags:0x202 cs:0x33 ss:0x2b ds:0x0 es:0x0 fs:0x0 gs:0x0 orig_rax:0xe7
}
{
  global_time:8063, event:`EXIT' tid:18879, ticks:8770923
}
{
  global_time:8064, event:`SIGNAL: SIGCHLD(async)' tid:18881, ticks:0 rax:0x0 rbx:0x2b7c1d50c700 rcx:0xffffffffffffffff rdx:0x2b7c1d50c9d0 rsi:0x2b7c1d50bf70 rdi:0x3d0f00 rbp:0x7fff41269100 rsp:0x2b7c1d50bf70 r8:0x2b7c1d50c700 r9:0x2b7c1d50c700 r10:0x2b7c1d50c9d0 r11:0x202 r12:0x0 r13:0x0 r14:0x2b7c1d50c9c0 r15:0x2b7c1d50c700 rip:0x2b7c08884441 eflags:0x202 cs:0x33 ss:0x2b ds:0x0 es:0x0 fs:0x0 gs:0x0 orig_rax:0x38
}
{
  global_time:8065, event:`SIGNAL_DELIVERY: SIGCHLD(async)' tid:18881, ticks:0 rax:0x0 rbx:0x2b7c1d50c700 rcx:0xffffffffffffffff rdx:0x2b7c1d50c9d0 rsi:0x2b7c1d50bf70 rdi:0x3d0f00 rbp:0x7fff41269100 rsp:0x2b7c1d50bf70 r8:0x2b7c1d50c700 r9:0x2b7c1d50c700 r10:0x2b7c1d50c9d0 r11:0x202 r12:0x0 r13:0x0 r14:0x2b7c1d50c9c0 r15:0x2b7c1d50c700 rip:0x2b7c08884441 eflags:0x202 cs:0x33 ss:0x2b ds:0x0 es:0x0 fs:0x0 gs:0x0 orig_rax:0x38
}
{
  global_time:8066, event:`SEGV_RDTSC' tid:18881, ticks:3 rax:0xdc4a5aae rbx:0x2b7c1d50c700 rcx:0xffffffffffffffff rdx:0x8e7bf rsi:0x2b7c1d50bf70 rdi:0x2b7c1d50c700 rbp:0x0 rsp:0x2b7c1d50bee0 r8:0x2b7c1d50c700 r9:0x2b7c1d50c700 r10:0x2b7c1d50c9d0 r11:0x202 r12:0x0 r13:0x0 r14:0x2b7c1d50c9c0 r15:0x2b7c1d50c700 rip:0x2b7c07b500d2 eflags:0x10202 cs:0x33 ss:0x2b ds:0x0 es:0x0 fs:0x0 gs:0x0 orig_rax:0xffffffffffffffff
}

When I record with -n the replay runs fine.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the failure in rr/src/ReplaySession.cc around guard_unexpected_signal() and reproduce using the ./mach crashtest command, --debugger=rr, and rr replay. Compare this recording with the -n recording that replays successfully, focusing on the SIGCHLD and subsequent signal events around global time 8064. Done means the recording no longer aborts with the unexpected-signal assertion.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp, linux
Domain
devtools, operating-systems, reverse-engineering
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.