Comment #7 on issue 9615 by ElideBotton: Crash in
HistoryBackend::~HistoryBackend while exiting Chrome browser process
http://code.google.com/p/chromium/issues/detail?id=9615
Hit another heap corruption crash, this time in v1.0.154.53.
FAULTING_IP:
+0
00000000 ?? ???
EXCEPTION_RECORD: ffffffff -- (.exr 0xffffffffffffffff)
ExceptionAddress: 00000000
ExceptionCode: 80000007 (Wake debugger)
ExceptionFlags: 00000000
NumberParameters: 0
FAULTING_THREAD: 00000000
PROCESS_NAME: chrome.exe
ERROR_CODE: (NTSTATUS) 0x80000007 - {Kernel Debugger Awakened} the system
debugger
was awakened by an interrupt.
NTGLOBALFLAG: 0
APPLICATION_VERIFIER_FLAGS: 0
READ_ADDRESS: 3839306e
BUGCHECK_STR: ACCESS_VIOLATION
DERIVED_WAIT_CHAIN:
Dl Eid Cid WaitType
-- --- ------- --------------------------
0 ca0.1590 Unknown
WAIT_CHAIN_COMMAND: ~0s;k;;
BLOCKING_THREAD: 00001590
DEFAULT_BUCKET_ID: APPLICATION_HANG_HeapCorruption
PRIMARY_PROBLEM_CLASS: APPLICATION_HANG_HeapCorruption
LAST_CONTROL_TRANSFER: from 7c90e9ab to 7c90eb94
STACK_TEXT:
0012df8c 7c90e9ab 7c86372c 00000002 0012e0dc ntdll!KiFastSystemCallRet
0012df90 7c86372c 00000002 0012e0dc 00000001
ntdll!ZwWaitForMultipleObjects+0xc
0012e6d8 7c8436da 0012e700 7c839b09 0012e708
kernel32!UnhandledExceptionFilter+0x8e4
0012e6e0 7c839b09 0012e708 00000000 0012e708 kernel32!BaseProcessStart+0x39
0012e708 7c9037bf 0012e7f4 0012ffe0 0012e810 kernel32!_except_handler3+0x61
0012e72c 7c90378b 0012e7f4 0012ffe0 0012e810 ntdll!ExecuteHandler2+0x26
0012e7dc 7c90eafa 00000000 0012e810 0012e7f4 ntdll!ExecuteHandler+0x24
0012e7dc 7c910f29 00000000 0012e810 0012e7f4
ntdll!KiUserExceptionDispatcher+0xe
0012eae8 7c910d5c 00c00000 3839306e 0012eba0
ntdll!RtlpCoalesceFreeBlocks+0x36e
0012ebbc 015b192c 00c00000 00000000 02580600 ntdll!RtlFreeHeap+0x2e9
0012ebfc 012b101b 02580600 03c72a68 03c72b1c chrome_1000000!free+0x6e
[f:\sp\vctools\crt_bld\self_x86\crt\src\free.c @ 110]
0012ecb8 01242191 024452a8 03c72a68 00000000 chrome_1000000!
CommandController::~CommandController+0x15c [c:\b\slave\chrome-
official\build\src\chrome\browser\controller.cc @ 27]
0012ed60 01241eff 03c72a68 024452a8 015884f4
chrome_1000000!Browser::~Browser+0x27e
[c:\b\slave\chrome-official\build\src\chrome\browser\browser.cc @ 316]
0012ed6c 015884f4 00000001 024452a8 024452a8 chrome_1000000!Browser::`scalar
deleting destructor'+0x9
0012ee14 015853d6 7e4188a6 024452a8 024452a8 chrome_1000000!
XPFrame::DestroyBrowser+0xcc [c:\b\slave\chrome-
official\build\src\chrome\browser\views\old_frames\xp_frame.cc @ 2446]
0012ee2c 01586621 00000001 012d0452 003604cc
chrome_1000000!XPFrame::~XPFrame+0x2c
[c:\b\slave\chrome-official\build\src\chrome\browser\views\old_frames\xp_frame.cc
@
358]
0012ee34 012d0452 003604cc 0012eed8 00fb0f90 chrome_1000000!
XPFrame::OnFinalMessage+0x11 [c:\b\slave\chrome-
official\build\src\chrome\browser\views\old_frames\xp_frame.cc @ 894]
0012ee70 7e418734 00000000 00000000 00000000 chrome_1000000!
ATL::CWindowImplBaseT<ATL::CWindow,ATL::CWinTraits<2181038080,0>
>::WindowProc+0xdf
[c:\program files (x86)\microsoft visual studio
8\vc\atlmfc\include\atlwin.h @ 3102]
0012ee9c 7e418816 00fb0f90 003604cc 00000082 USER32!InternalCallWinProc+0x28
0012ef04 7e41c63f 00000000 00fb0f90 003604cc
USER32!UserCallWinProcCheckWow+0x150
0012ef34 7e41c665 00fb0f90 003604cc 00000082 USER32!CallWindowProcAorW+0x98
0012ef54 015239d4 00fb0f90 003604cc 00000082 USER32!CallWindowProcW+0x1b
0012f014 7e418734 003604cc 00000082 00000000 chrome_1000000!
views::FocusWindowCallback+0x115 [c:\b\slave\chrome-
official\build\src\chrome\views\focus_manager.cc @ 199]
0012f040 7e41d05b 015238bf 003604cc 00000082 USER32!InternalCallWinProc+0x28
0012f0a8 7e41b4c0 00000000 015238bf 003604cc
USER32!UserCallWinProcCheckWow+0xea
0012f0fc 7e41dabd 006e3600 00000082 00000000
USER32!DispatchClientMessage+0xa3
0012f12c 7c90eae3 0012f13c 00000018 006e3600 USER32!__fnNCDESTROY+0x26
0012f150 7e41daf6 01586609 003604cc 03c40360
ntdll!KiUserCallbackDispatcher+0x13
0012f178 0100b1f8 0012f258 0012f4b0 00000000 USER32!NtUserDestroyWindow+0xc
0012f21c 0100b234 03c40360 00c4ee30 0100b429 chrome_1000000!
MessageLoop::RunTask+0x7c
[c:\b\slave\chrome-official\build\src\base\message_loop.cc
@ 304]
0012f228 0100b429 00c07220 00c071f8 00000000 chrome_1000000!
MessageLoop::DeferOrRunPendingTask+0x28 [c:\b\slave\chrome-
official\build\src\base\message_loop.cc @ 314]
0012f258 01018bdd 00000000 00c071f8 00000000
chrome_1000000!MessageLoop::DoWork+0x6e
[c:\b\slave\chrome-official\build\src\base\message_loop.cc @ 403]
0012f270 0101877e 0012f4b0 0012f4b0 02441e20 chrome_1000000!
base::MessagePumpForUI::DoRunLoop+0x18 [c:\b\slave\chrome-
official\build\src\base\message_pump_win.cc @ 331]
0012f28c 0100af2d 02441e20 0012f4b0 0012f648 chrome_1000000!
base::MessagePumpWin::RunWithDispatcher+0x38 [c:\b\slave\chrome-
official\build\src\base\message_pump_win.cc @ 97]
0012f330 0100aea7 ce1551fa 00000000 0012f648 chrome_1000000!
MessageLoop::RunInternal+0x80 [c:\b\slave\chrome-
official\build\src\base\message_loop.cc @ 188]
0012f368 0100b6e5 00000001 00000000 02441e20 chrome_1000000!
MessageLoop::RunHandler+0x4f [c:\b\slave\chrome-
official\build\src\base\message_loop.cc @ 176]
0012f384 011fd75f 02441e20 00000001 0012f6cc chrome_1000000!
MessageLoopForUI::Run+0x21 [c:\b\slave\chrome-
official\build\src\base\message_loop.cc @ 554]
0012f66c 01003456 0012f698 00000001 00a34eb8
chrome_1000000!BrowserMain+0xdb5
[c:\b\slave\chrome-official\build\src\chrome\browser\browser_main.cc @ 568]
0012f7e0 00402ab0 00400000 0012fc94 00020c04 chrome_1000000!ChromeMain+0x568
[c:\b\slave\chrome-official\build\src\chrome\app\chrome_dll_main.cc @ 224]
0012fc64 0040251c 00400000 0012fc94 00020c04 chrome!
google_update::GoogleUpdateClient::Launch+0x1a0 [c:\b\slave\chrome-
official\build\src\chrome\app\google_update_client.cc @ 95]
0012ff28 0043575f 00400000 00000000 00020c04 chrome!wWinMain+0x15f
[c:\b\slave\chrome-official\build\src\chrome\app\chrome_exe_main.cc @ 66]
0012ffc0 7c816fd7 80000001 0007d220 7ffde000 chrome!__tmainCRTStartup+0x176
[f:\sp\vctools\crt_bld\self_x86\crt\src\crt0.c @ 324]
0012fff0 00000000 004357c8 00000000 78746341 kernel32!BaseProcessStart+0x23
FOLLOWUP_IP:
chrome_1000000!free+6e [f:\sp\vctools\crt_bld\self_x86\crt\src\free.c @ 110]
015b192c 85c0 test eax,eax
SYMBOL_STACK_INDEX: a
SYMBOL_NAME: chrome_1000000!free+6e
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: chrome_1000000
IMAGE_NAME: chrome.dll
DEBUG_FLR_IMAGE_TIMESTAMP: 49bf1517
STACK_COMMAND: ~0s ; kb
BUCKET_ID: ACCESS_VIOLATION_chrome_1000000!free+6e
FAILURE_BUCKET_ID: chrome.dll!free_80000007_APPLICATION_HANG_HeapCorruption
--
You received this message because you are listed in the owner
or CC fields of this issue, or because you starred this issue.
You may adjust your issue notification preferences at:
http://code.google.com/hosting/settings
--~--~---------~--~----~------------~-------~--~----~
Automated mail from issue updates at http://crbug.com/
Subscription options: http://groups.google.com/group/chromium-bugs
-~----------~----~----~----~------~----~------~--~---