Open Bug 2055560 Opened 2 months ago Updated 20 days ago

Crash in [@ ac_init_shared_llvm_once]

Categories

(Core :: Graphics, defect)

defect

Tracking

()

REOPENED
157 Branch
Tracking Status
firefox157 --- affected

People

(Reporter: afranchuk, Assigned: aosmond, NeedInfo)

References

(Blocks 1 open bug)

Details

(Keywords: crash, topcrash)

Crash Data

Attachments

(1 file)

Crash report: https://crash-stats.mozilla.org/report/index/c3059c3c-2d9a-4f33-814a-6742d0260716

Reason:

SIGSEGV / SEGV_MAPERR

Top 10 frames:

0  libgallium-25.2.8-0ubuntu0.24.04.2.so  ac_init_shared_llvm_once
1  libgallium-25.2.8-0ubuntu0.24.04.2.so  ac_init_shared_llvm_once
2  libgallium-25.2.8-0ubuntu0.24.04.2.so  ac_init_shared_llvm_once
3  libgallium-25.2.8-0ubuntu0.24.04.2.so  std::vector<unsigned int, std::allocator<unsigned int> >::_M_default_append(u...
4  libgallium-25.2.8-0ubuntu0.24.04.2.so  std::vector<unsigned int, std::allocator<unsigned int> >::_M_default_append(u...
5  libgallium-25.2.8-0ubuntu0.24.04.2.so  std::vector<unsigned int, std::allocator<unsigned int> >::_M_default_append(u...
6  libgallium-25.2.8-0ubuntu0.24.04.2.so  std::vector<unsigned int, std::allocator<unsigned int> >::_M_default_append(u...
7  libgallium-25.2.8-0ubuntu0.24.04.2.so  ac_init_shared_llvm_once
8  libgallium-25.2.8-0ubuntu0.24.04.2.so  ac_init_shared_llvm_once
9  libgallium-25.2.8-0ubuntu0.24.04.2.so  std::vector<unsigned int, std::allocator<unsigned int> >::_M_default_append(u...

This signature is currently the 13th top crasher on Linux, increasing significantly since 152. Bug 1988197 may have included this previously. As recently as January 2026 there were no crashes whatsoever.

The bug is linked to a topcrash signature, which matches the following criterion:

  • Top 5 desktop browser crashes on Linux on release

For more information, please visit BugBot documentation.

Keywords: topcrash

The severity field is not set for this bug.
:bhood, could you have a look please?

For more information, please visit BugBot documentation.

Flags: needinfo?(bhood)

I'd bet that the ac_init_shared_llvm_once, std::vector, and vdp_imp_device_create_x11 things are simply failures to symbolicate the frame's address, and are meaningless. The only thing real in the crash listed in comment 0 are stack frames 21 and older.

We should consider adding those strings to the list of ignored functions for generating crash signatures.

All crashes are in driver version 25.2.8.0.

Our operating theory is that this is a threading bug in nouveau driver in mesa 25.2.8.0, we previously blocklisted use of threading on older versions of that driver, so we should just expand that blocklist to cover all versions.

Flags: needinfo?(bhood) → needinfo?(aosmond)

The bug is linked to a topcrash signature, which matches the following criteria:

  • Top 20 desktop browser crashes on release (startup)
  • Top 5 desktop browser crashes on Linux on release (startup)

For more information, please visit BugBot documentation.

This can be revisited/re-enabled in the future once stable.

I created a downloadable blocklist entry pending review.

Flags: needinfo?(aosmond)
Assignee: nobody → aosmond
Status: NEW → ASSIGNED

There is an r+ patch which didn't land and no activity in this bug for 1 week.
:aosmond, could you have a look please?
If you still have some work to do, you can add an action "Plan Changes" in Phabricator.
For more information, please visit BugBot documentation.

Flags: needinfo?(aosmond)
Flags: needinfo?(ahale)
Pushed by bwerth@mozilla.com: https://github.com/mozilla-firefox/firefox/commit/4c1a8d248689 https://hg.mozilla.org/integration/autoland/rev/75f15614ca13 Block Mesa threading with nouveau devices due to crash volume. r=gfx-reviewers,lsalzman,ahale
Status: ASSIGNED → RESOLVED
Closed: 1 month ago
Resolution: --- → FIXED
Target Milestone: --- → 157 Branch

It doesn't seem like blocklisting the MESA_THREADING feature is helping. Something else is causing this crash, unfortunately.

Status: RESOLVED → REOPENED
Resolution: FIXED → ---

Based on the topcrash criteria, the crash signature linked to this bug is not a topcrash signature anymore.

For more information, please visit BugBot documentation.

Bug 1852794 is the one where we added the mesa threading feature block.

I will double-check the downloadable blocklist entry. As noted by @jimb, it's weird that volume is way low on Nightly but increasing in Release, making it look like we've found a fix that isn't percolating to Release. If the fix was the blocklist entry, then the downloadable blocklist is our mechanism for advancing that to Release.

Something that seems notable is that the affected Mesa driver version is almost exclusively 25.2.8.0, which presumably is shipping in Firefox snap packages currently in Ubuntu and Linux Mint and others, it seems likely this driver version has a bug, and nightly is not packaged in snap so it would get the system version of Mesa instead which is probably a different version.

(In reply to Brad Werth [:bradwerth] from comment #16)

I will double-check the downloadable blocklist entry. As noted by @jimb, it's weird that volume is way low on Nightly but increasing in Release, making it look like we've found a fix that isn't percolating to Release. If the fix was the blocklist entry, then the downloadable blocklist is our mechanism for advancing that to Release.

Downloadable blocklist entry is https://remote-settings.mozilla.org/v1/admin/#/buckets/staging/collections/gfx/records/aefaa076-01de-431a-81bc-e6aa2f6b84fc, which Andrew created and I approved. In theory it attempts to block MESA_THREADING for all mesa/nouveau drivers, matching the code blocklist attachment 9624088 [details]. I have two areas of uncertainty, which I hope Andrew can address:

  1. The link to the entry doesn't show MESA_THREADING, though it appears on the "records" view one level up. MESA_THREADING doesn't appear on the Feature dropdown at all, so this makes me feel like it isn't properly integrated into the blocklist somehow.
  2. It uses BLOCKED_DRIVER_VERSION with no min and a max of "155.*". I wonder if that is properly matching all driver versions. Too bad we don't have an explicit enum BLOCKED_DRIVER_ALL_VERSIONS.
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: