crash log for renderer (pid 7775): STDOUT: #CRASHED - renderer (pid 7775) STDERR: ================================================================= STDERR: ==4==ERROR: AddressSanitizer: use-after-poison on address 0x7ec1c5576088 at pc 0x0000042ed427 bp 0x7fffcda2a440 sp 0x7fffcda2a438 STDERR: READ of size 8 at 0x7ec1c5576088 thread T0 (content_shell) STDERR: #0 0x42ed426 in IsEmpty v8/include/v8.h:511:43 STDERR: #1 0x42ed426 in Reset v8/include/v8.h:7320:0 STDERR: #2 0x42ed426 in disposeWrapper third_party/WebKit/Source/bindings/core/v8/ScriptWrappable.h:178:0 STDERR: #3 0x42ed426 in blink::ScriptWrappable::firstWeakCallback(v8::WeakCallbackInfo const&) third_party/WebKit/Source/bindings/core/v8/ScriptWrappable.h:184:0 STDERR: #4 0x257584f in Invoke v8/src/global-handles.cc:967:3 STDERR: #5 0x257584f in v8::internal::GlobalHandles::DispatchPendingPhantomCallbacks(bool) v8/src/global-handles.cc:933:0 STDERR: #6 0x257616a in v8::internal::GlobalHandles::PostGarbageCollectionProcessing(v8::internal::GarbageCollector, v8::GCCallbackFlags) v8/src/global-handles.cc:988:18 STDERR: #7 0x258c5e5 in v8::internal::Heap::PerformGarbageCollection(v8::internal::GarbageCollector, v8::GCCallbackFlags) v8/src/heap/heap.cc:1304:9 STDERR: #8 0x258a526 in v8::internal::Heap::CollectGarbage(v8::internal::GarbageCollector, char const*, char const*, v8::GCCallbackFlags) v8/src/heap/heap.cc:980:11 STDERR: #9 0x24fe884 in CollectGarbage v8/src/heap/heap-inl.h:532:10 STDERR: #10 0x24fe884 in v8::internal::Factory::NewFixedArray(int, v8::internal::PretenureFlag) v8/src/factory.cc:128:0 STDERR: #11 0x2777711 in New v8/src/objects.cc:15752:30 STDERR: #12 0x2777711 in New v8/src/objects.cc:16767:0 STDERR: #13 0x2777711 in v8::internal::JSObject::MigrateFastToSlow(v8::internal::Handle, v8::internal::Handle, int) v8/src/objects.cc:5156:0 STDERR: #14 0x271d27e in v8::internal::LookupIterator::Delete() v8/src/lookup.cc:285:7 STDERR: #15 0x279fe61 in v8::internal::JSReceiver::DeleteProperty(v8::internal::LookupIterator*, v8::internal::LanguageMode) v8/src/objects.cc:5882:9 STDERR: #16 0x29fcef3 in v8::internal::Runtime::DeleteObjectProperty(v8::internal::Isolate*, v8::internal::Handle, v8::internal::Handle, v8::internal::LanguageMode) v8/src/runtime/runtime-object.cc:130:10 STDERR: #17 0x20f6fb4 in v8::Object::Delete(v8::Local, v8::Local) v8/src/api.cc:3862:8 STDERR: #18 0x5fcb1f5 in blink::V8HiddenValue::deleteHiddenValue(blink::ScriptState*, v8::Local, v8::Local) third_party/WebKit/Source/bindings/core/v8/V8HiddenValue.cpp:46:26 STDERR: #19 0x5fa91d9 in clearWrapper third_party/WebKit/Source/bindings/core/v8/V8EventListenerList.h:68:9 STDERR: #20 0x5fa91d9 in blink::V8AbstractEventListener::~V8AbstractEventListener() third_party/WebKit/Source/bindings/core/v8/V8AbstractEventListener.cpp:62:0 STDERR: #21 0x2040a63 in finalize third_party/WebKit/Source/platform/heap/HeapPage.cpp:104:9 STDERR: #22 0x2040a63 in blink::NormalPage::sweep() third_party/WebKit/Source/platform/heap/HeapPage.cpp:1148:0 STDERR: #23 0x203b6f0 in sweepUnsweptPage third_party/WebKit/Source/platform/heap/HeapPage.cpp:323:9 STDERR: #24 0x203b6f0 in blink::BaseHeap::completeSweep() third_party/WebKit/Source/platform/heap/HeapPage.cpp:364:0 STDERR: #25 0x20571b0 in blink::ThreadState::eagerSweep() third_party/WebKit/Source/platform/heap/ThreadState.cpp:1083:9 STDERR: #26 0x20566d7 in blink::ThreadState::preSweep() third_party/WebKit/Source/platform/heap/ThreadState.cpp:1029:5 STDERR: #27 0x2034bcd in ~SafePointScope third_party/WebKit/Source/platform/heap/SafePoint.h:28:13 STDERR: #28 0x2034bcd in blink::Heap::collectGarbage(blink::BlinkGC::StackState, blink::BlinkGC::GCType, blink::BlinkGC::GCReason) third_party/WebKit/Source/platform/heap/Heap.cpp:468:0 STDERR: #29 0x5fc0f5d in blink::V8GCController::gcPrologue(v8::GCType, v8::GCCallbackFlags) third_party/WebKit/Source/bindings/core/v8/V8GCController.cpp:278:9 STDERR: #30 0x258ba35 in CallGCPrologueCallbacks v8/src/heap/heap.cc:1356:9 STDERR: #31 0x258ba35 in v8::internal::Heap::PerformGarbageCollection(v8::internal::GarbageCollector, v8::GCCallbackFlags) v8/src/heap/heap.cc:1251:0 STDERR: #32 0x258a526 in v8::internal::Heap::CollectGarbage(v8::internal::GarbageCollector, char const*, char const*, v8::GCCallbackFlags) v8/src/heap/heap.cc:980:11 STDERR: #33 0x24fe884 in CollectGarbage v8/src/heap/heap-inl.h:532:10 STDERR: #34 0x24fe884 in v8::internal::Factory::NewFixedArray(int, v8::internal::PretenureFlag) v8/src/factory.cc:128:0 STDERR: #35 0x27c3100 in Allocate v8/src/objects.cc:9726:31 STDERR: #36 0x27c3100 in v8::internal::DescriptorArray::CopyUpToAddAttributes(v8::internal::Handle, int, PropertyAttributes, int) v8/src/objects.cc:8986:0 STDERR: #37 0x278c6be in CopyUpTo v8/src/objects.cc:8969:10 STDERR: #38 0x278c6be in v8::internal::Map::EnsureDescriptorSlack(v8::internal::Handle, int) v8/src/objects.cc:4192:0 STDERR: #39 0x27c1d59 in v8::internal::Map::ShareDescriptor(v8::internal::Handle, v8::internal::Handle, v8::internal::Descriptor*) v8/src/objects.cc:8385:7 STDERR: #40 0x2771393 in v8::internal::Map::CopyAddDescriptor(v8::internal::Handle, v8::internal::Descriptor*, v8::internal::TransitionFlag) v8/src/objects.cc:8929:12 STDERR: #41 0x27c5d87 in v8::internal::Map::TransitionToAccessorProperty(v8::internal::Handle, v8::internal::Handle, v8::internal::AccessorComponent, v8::internal::Handle, PropertyAttributes) v8/src/objects.cc:8913:10 STDERR: #42 0x271d7ba in v8::internal::LookupIterator::TransitionToAccessorProperty(v8::internal::AccessorComponent, v8::internal::Handle, PropertyAttributes) v8/src/lookup.cc:307:19 STDERR: #43 0x27a7ef8 in v8::internal::JSObject::DefineAccessor(v8::internal::LookupIterator*, v8::internal::Handle, v8::internal::Handle, PropertyAttributes) v8/src/objects.cc:8055:5 STDERR: #44 0x27bfc32 in v8::internal::JSObject::DefineAccessor(v8::internal::Handle, v8::internal::Handle, v8::internal::Handle, v8::internal::Handle, PropertyAttributes) v8/src/objects.cc:8012:10 STDERR: #45 0x2144202 in DefineAccessorProperty v8/src/api-natives.cc:60:3 STDERR: #46 0x2144202 in v8::internal::(anonymous namespace)::ConfigureInstance(v8::internal::Isolate*, v8::internal::Handle, v8::internal::Handle) v8/src/api-natives.cc:181:0 STDERR: #47 0x2142c3f in v8::internal::(anonymous namespace)::InstantiateObject(v8::internal::Isolate*, v8::internal::Handle) v8/src/api-natives.cc:223:3 STDERR: #48 0x2140fe0 in v8::internal::(anonymous namespace)::InstantiateFunction(v8::internal::Isolate*, v8::internal::Handle, v8::internal::Handle) v8/src/api-natives.cc:268:7 STDERR: #49 0x2141306 in v8::internal::(anonymous namespace)::InstantiateFunction(v8::internal::Isolate*, v8::internal::Handle, v8::internal::Handle) v8/src/api-natives.cc:277:7 STDERR: #50 0x2140712 in v8::internal::ApiNatives::InstantiateFunction(v8::internal::Handle) v8/src/api-natives.cc:359:10 STDERR: #51 0x20fdbc7 in v8::FunctionTemplate::GetFunction(v8::Local) v8/src/api.cc:5680:26 STDERR: #52 0x5fe0631 in blink::V8PerContextData::constructorForTypeSlowCase(blink::WrapperTypeInfo const*) third_party/WebKit/Source/bindings/core/v8/V8PerContextData.cpp:108:10 STDERR: #53 0x5fe03c0 in constructorForType third_party/WebKit/Source/bindings/core/v8/V8PerContextData.h:86:65 STDERR: #54 0x5fe03c0 in blink::V8PerContextData::createWrapperFromCacheSlowCase(blink::WrapperTypeInfo const*) third_party/WebKit/Source/bindings/core/v8/V8PerContextData.cpp:86:0 STDERR: #55 0x5fbf18a in createWrapperFromCache third_party/WebKit/Source/bindings/core/v8/V8PerContextData.h:80:64 STDERR: #56 0x5fbf18a in blink::V8DOMWrapper::createWrapper(v8::Isolate*, v8::Local, blink::WrapperTypeInfo const*, blink::ScriptWrappable*) third_party/WebKit/Source/bindings/core/v8/V8DOMWrapper.cpp:86:0 STDERR: #57 0x43a3d8b in blink::Node::wrap(v8::Isolate*, v8::Local) third_party/WebKit/Source/core/dom/Node.cpp:2343:37 STDERR: #58 0x6623593 in v8SetReturnValueFast > third_party/WebKit/Source/bindings/core/v8/V8Binding.h:352:37 STDERR: #59 0x6623593 in indexedPropertyGetter /mnt/data/b/build/slave/WebKit_Linux_Oilpan_ASAN/build/src/out/Release/gen/blink/bindings/core/v8/V8HTMLCollection.cpp:111:0 STDERR: #60 0x6623593 in blink::HTMLCollectionV8Internal::indexedPropertyGetterCallback(unsigned int, v8::PropertyCallbackInfo const&) /mnt/data/b/build/slave/WebKit_Linux_Oilpan_ASAN/build/src/out/Release/gen/blink/bindings/core/v8/V8HTMLCollection.cpp:117:0 STDERR: #61 0x2cb4bcd in v8::internal::PropertyCallbackArguments::Call(void (*)(unsigned int, v8::PropertyCallbackInfo const&), unsigned int) v8/src/arguments.cc:86:1 STDERR: #62 0x274ba6c in v8::internal::JSObject::GetPropertyWithInterceptor(v8::internal::LookupIterator*, bool*) v8/src/objects.cc:14893:14 STDERR: #63 0x274af0c in v8::internal::Object::GetProperty(v8::internal::LookupIterator*, v8::internal::LanguageMode) v8/src/objects.cc:697:9 STDERR: #64 0x29fcc7d in v8::internal::Runtime::GetObjectProperty(v8::internal::Isolate*, v8::internal::Handle, v8::internal::Handle, v8::internal::LanguageMode) v8/src/runtime/runtime-object.cc:35:10 STDERR: #65 0x26a6b6a in v8::internal::KeyedLoadIC::Load(v8::internal::Handle, v8::internal::Handle) v8/src/ic/ic.cc:1402:3 STDERR: #66 0x26b21da in __RT_impl_Runtime_KeyedLoadIC_Miss v8/src/ic/ic.cc:2286:3 STDERR: #67 0x26b21da in v8::internal::Runtime_KeyedLoadIC_Miss(int, v8::internal::Object**, v8::internal::Isolate*) v8/src/ic/ic.cc:2272:0 STDERR: #47 0x7fcc5030a85a () STDERR: #48 0x7fcc50423630 () STDERR: #49 0x7fcc50336fc3 () STDERR: #50 0x7fcc5031b6c1 () STDERR: #68 0x24eee15 in v8::internal::(anonymous namespace)::Invoke(v8::internal::Isolate*, bool, v8::internal::Handle, v8::internal::Handle, int, v8::internal::Handle*, v8::internal::Handle) v8/src/execution.cc:98:13 STDERR: #69 0x24ee183 in v8::internal::Execution::Call(v8::internal::Isolate*, v8::internal::Handle, v8::internal::Handle, int, v8::internal::Handle*) v8/src/execution.cc:167:10 STDERR: #70 0x20c2d79 in v8::Script::Run(v8::Local) v8/src/api.cc:1724:23 STDERR: #71 0x5fec01c in blink::V8ScriptRunner::runCompiledScript(v8::Isolate*, v8::Local, blink::ExecutionContext*) third_party/WebKit/Source/bindings/core/v8/V8ScriptRunner.cpp:393:18 STDERR: #72 0x5f554bc in blink::ScriptController::executeScriptAndReturnValue(v8::Local, blink::ScriptSourceCode const&, blink::AccessControlStatus, double*) third_party/WebKit/Source/bindings/core/v8/ScriptController.cpp:190:21 STDERR: #73 0x5f5b953 in blink::ScriptController::evaluateScriptInMainWorld(blink::ScriptSourceCode const&, blink::AccessControlStatus, blink::ScriptController::ExecuteScriptPolicy, double*) third_party/WebKit/Source/bindings/core/v8/ScriptController.cpp:566:35 STDERR: #74 0x5f5c08e in blink::ScriptController::executeScriptInMainWorld(blink::ScriptSourceCode const&, blink::AccessControlStatus, double*) third_party/WebKit/Source/bindings/core/v8/ScriptController.cpp:539:5 STDERR: #75 0x452e995 in blink::ScriptLoader::executeScript(blink::ScriptSourceCode const&, double*) third_party/WebKit/Source/core/dom/ScriptLoader.cpp:403:5 STDERR: #76 0x48eeaa5 in blink::HTMLScriptRunner::executePendingScriptAndDispatchEvent(blink::PendingScript&, blink::PendingScript::Type) third_party/WebKit/Source/core/html/parser/HTMLScriptRunner.cpp:157:18 STDERR: #77 0x48ee4ae in blink::HTMLScriptRunner::executeParsingBlockingScript() third_party/WebKit/Source/core/html/parser/HTMLScriptRunner.cpp:125:5 STDERR: #78 0x48f00d7 in blink::HTMLScriptRunner::executeParsingBlockingScripts() third_party/WebKit/Source/core/html/parser/HTMLScriptRunner.cpp:235:9 STDERR: #79 0x48cb82c in blink::HTMLDocumentParser::notifyScriptLoaded(blink::Resource*) third_party/WebKit/Source/core/html/parser/HTMLDocumentParser.cpp:1069:5 STDERR: #80 0x4f48b67 in blink::Resource::checkNotify() third_party/WebKit/Source/core/fetch/Resource.cpp:248:9 STDERR: #81 0x4f4a6dd in blink::Resource::finish() third_party/WebKit/Source/core/fetch/Resource.cpp:319:5 STDERR: #82 0x4f7bd40 in blink::ResourceLoader::didFinishLoading(blink::WebURLLoader*, double, long) third_party/WebKit/Source/core/fetch/ResourceLoader.cpp:449:5 STDERR: #83 0x79090f8 in content::WebURLLoaderImpl::Context::OnCompletedRequest(int, bool, bool, std::__1::basic_string, std::__1::allocator > const&, base::TimeTicks const&, long) content/child/web_url_loader_impl.cc:747:7 STDERR: #84 0x78e32e0 in content::ResourceDispatcher::OnRequestComplete(int, ResourceMsg_RequestCompleteData const&) content/child/resource_dispatcher.cc:377:3 STDERR: #85 0x78dd33d in DispatchToMethodImpl base/tuple.h:254:3 STDERR: #86 0x78dd33d in DispatchToMethod base/tuple.h:261:0 STDERR: #87 0x78dd33d in Dispatch content/common/resource_messages.h:363:0 STDERR: #88 0x78dd33d in content::ResourceDispatcher::DispatchMessage(IPC::Message const&) content/child/resource_dispatcher.cc:525:0 STDERR: #89 0x78dc15e in content::ResourceDispatcher::OnMessageReceived(IPC::Message const&) content/child/resource_dispatcher.cc:119:3 STDERR: #90 0x79a8581 in Run base/bind_internal.h:159:12 STDERR: #91 0x79a8581 in MakeItSo base/bind_internal.h:295:0 STDERR: #92 0x79a8581 in base::internal::Invoker, base::internal::BindState >)>, void (scoped_ptr >), base::internal::TypeList > > > >, base::internal::TypeList > > > >, base::internal::InvokeHelper >)>, base::internal::TypeList > > >, void ()>::Run(base::internal::BindStateBase*) base/bind_internal.h:345:0 STDERR: #93 0x6d8fc4 in Run base/callback.h:396:12 STDERR: #94 0x6d8fc4 in base::debug::TaskAnnotator::RunTask(char const*, base::PendingTask const&) base/debug/task_annotator.cc:51:0 STDERR: #95 0x79bda02 in scheduler::TaskQueueManager::ProcessTaskFromWorkQueue(scheduler::internal::TaskQueueImpl*, scheduler::internal::TaskQueueImpl::Task*) components/scheduler/base/task_queue_manager.cc:357:3 STDERR: #96 0x79b96f0 in scheduler::TaskQueueManager::DoWork(bool) components/scheduler/base/task_queue_manager.cc:282:13 STDERR: #97 0x6d8fc4 in Run base/callback.h:396:12 STDERR: #98 0x6d8fc4 in base::debug::TaskAnnotator::RunTask(char const*, base::PendingTask const&) base/debug/task_annotator.cc:51:0 STDERR: #99 0x61148f in base::MessageLoop::RunTask(base::PendingTask const&) base/message_loop/message_loop.cc:481:3 STDERR: #100 0x612914 in DeferOrRunPendingTask base/message_loop/message_loop.cc:490:5 STDERR: #101 0x612914 in base::MessageLoop::DoWork() base/message_loop/message_loop.cc:602:0 STDERR: #102 0x6189b0 in base::MessagePumpDefault::Run(base::MessagePump::Delegate*) base/message_loop/message_pump_default.cc:32:21 STDERR: #103 0x636568 in base::RunLoop::Run() base/run_loop.cc:55:3 STDERR: #104 0x60fafe in base::MessageLoop::Run() base/message_loop/message_loop.cc:288:3 STDERR: #105 0x7ad1714 in content::RendererMain(content::MainFunctionParams const&) content/renderer/renderer_main.cc:219:7 STDERR: #106 0x5b2e1a in content::RunZygote(content::MainFunctionParams const&, content::ContentMainDelegate*) content/app/content_main_runner.cc:302:14 STDERR: #107 0x5b4ced in content::ContentMainRunnerImpl::Run() content/app/content_main_runner.cc:804:12 STDERR: #108 0x5b21fa in content::ContentMain(content::ContentMainParams const&) content/app/content_main.cc:19:15 STDERR: #109 0x4f3ff2 in main content/shell/app/shell_main.cc:49:10 STDERR: #110 0x7fcc8361176c in __libc_start_main /build/buildd/eglibc-2.15/csu/libc-start.c:226:0 STDERR: STDERR: AddressSanitizer can not describe address in more detail (wild memory access suspected). STDERR: SUMMARY: AddressSanitizer: use-after-poison (/mnt/data/b/build/slave/WebKit_Linux_Oilpan_ASAN/build/src/out/Release/content_shell+0x42ed426) STDERR: Shadow bytes around the buggy address: STDERR: 0x0fd8b8aa6bc0: f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 STDERR: 0x0fd8b8aa6bd0: f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 STDERR: 0x0fd8b8aa6be0: f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 STDERR: 0x0fd8b8aa6bf0: f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 STDERR: 0x0fd8b8aa6c00: f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 STDERR: =>0x0fd8b8aa6c10: f7[f7]f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 STDERR: 0x0fd8b8aa6c20: f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 STDERR: 0x0fd8b8aa6c30: f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 STDERR: 0x0fd8b8aa6c40: f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 STDERR: 0x0fd8b8aa6c50: f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 STDERR: 0x0fd8b8aa6c60: f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 f7 STDERR: Shadow byte legend (one shadow byte represents 8 application bytes): STDERR: Addressable: 00 STDERR: Partially addressable: 01 02 03 04 05 06 07 STDERR: Heap left redzone: fa STDERR: Heap right redzone: fb STDERR: Freed heap region: fd STDERR: Stack left redzone: f1 STDERR: Stack mid redzone: f2 STDERR: Stack right redzone: f3 STDERR: Stack partial redzone: f4 STDERR: Stack after return: f5 STDERR: Stack use after scope: f8 STDERR: Global redzone: f9 STDERR: Global init order: f6 STDERR: Poisoned by user: f7 STDERR: Container overflow: fc STDERR: Array cookie: ac STDERR: Intra object redzone: bb STDERR: ASan internal: fe STDERR: Left alloca redzone: ca STDERR: Right alloca redzone: cb STDERR: ==4==ABORTING