Crash in [@ ac_init_shared_llvm_once]
Categories
(Core :: Graphics, defect)
Tracking
()
| Tracking | Status | |
|---|---|---|
| firefox157 | --- | affected |
People
(Reporter: afranchuk, Assigned: aosmond, NeedInfo)
References
(Blocks 1 open bug)
Details
(Keywords: crash, topcrash)
Crash Data
Attachments
(1 file)
Crash report: https://crash-stats.mozilla.org/report/index/c3059c3c-2d9a-4f33-814a-6742d0260716
Reason:
SIGSEGV / SEGV_MAPERR
Top 10 frames:
0 libgallium-25.2.8-0ubuntu0.24.04.2.so ac_init_shared_llvm_once
1 libgallium-25.2.8-0ubuntu0.24.04.2.so ac_init_shared_llvm_once
2 libgallium-25.2.8-0ubuntu0.24.04.2.so ac_init_shared_llvm_once
3 libgallium-25.2.8-0ubuntu0.24.04.2.so std::vector<unsigned int, std::allocator<unsigned int> >::_M_default_append(u...
4 libgallium-25.2.8-0ubuntu0.24.04.2.so std::vector<unsigned int, std::allocator<unsigned int> >::_M_default_append(u...
5 libgallium-25.2.8-0ubuntu0.24.04.2.so std::vector<unsigned int, std::allocator<unsigned int> >::_M_default_append(u...
6 libgallium-25.2.8-0ubuntu0.24.04.2.so std::vector<unsigned int, std::allocator<unsigned int> >::_M_default_append(u...
7 libgallium-25.2.8-0ubuntu0.24.04.2.so ac_init_shared_llvm_once
8 libgallium-25.2.8-0ubuntu0.24.04.2.so ac_init_shared_llvm_once
9 libgallium-25.2.8-0ubuntu0.24.04.2.so std::vector<unsigned int, std::allocator<unsigned int> >::_M_default_append(u...
This signature is currently the 13th top crasher on Linux, increasing significantly since 152. Bug 1988197 may have included this previously. As recently as January 2026 there were no crashes whatsoever.
Comment 1•2 months ago
|
||
The bug is linked to a topcrash signature, which matches the following criterion:
- Top 5 desktop browser crashes on Linux on release
For more information, please visit BugBot documentation.
Comment 2•2 months ago
|
||
The severity field is not set for this bug.
:bhood, could you have a look please?
For more information, please visit BugBot documentation.
Updated•2 months ago
|
Comment 3•1 month ago
|
||
I'd bet that the ac_init_shared_llvm_once, std::vector, and vdp_imp_device_create_x11 things are simply failures to symbolicate the frame's address, and are meaningless. The only thing real in the crash listed in comment 0 are stack frames 21 and older.
We should consider adding those strings to the list of ignored functions for generating crash signatures.
Comment 4•1 month ago
|
||
All crashes are in driver version 25.2.8.0.
Comment 5•1 month ago
|
||
Our operating theory is that this is a threading bug in nouveau driver in mesa 25.2.8.0, we previously blocklisted use of threading on older versions of that driver, so we should just expand that blocklist to cover all versions.
Updated•1 month ago
|
Comment 7•1 month ago
|
||
The bug is linked to a topcrash signature, which matches the following criteria:
- Top 20 desktop browser crashes on release (startup)
- Top 5 desktop browser crashes on Linux on release (startup)
For more information, please visit BugBot documentation.
| Assignee | ||
Comment 8•1 month ago
|
||
This can be revisited/re-enabled in the future once stable.
| Assignee | ||
Comment 9•1 month ago
|
||
I created a downloadable blocklist entry pending review.
Updated•1 month ago
|
Comment 10•1 month ago
|
||
There is an r+ patch which didn't land and no activity in this bug for 1 week.
:aosmond, could you have a look please?
If you still have some work to do, you can add an action "Plan Changes" in Phabricator.
For more information, please visit BugBot documentation.
Comment 11•1 month ago
|
||
Comment 12•1 month ago
|
||
| bugherder | ||
Comment 13•1 month ago
|
||
It doesn't seem like blocklisting the MESA_THREADING feature is helping. Something else is causing this crash, unfortunately.
Updated•1 month ago
|
Comment 14•1 month ago
|
||
Based on the topcrash criteria, the crash signature linked to this bug is not a topcrash signature anymore.
For more information, please visit BugBot documentation.
Comment 15•27 days ago
|
||
Bug 1852794 is the one where we added the mesa threading feature block.
Comment 16•27 days ago
|
||
I will double-check the downloadable blocklist entry. As noted by @jimb, it's weird that volume is way low on Nightly but increasing in Release, making it look like we've found a fix that isn't percolating to Release. If the fix was the blocklist entry, then the downloadable blocklist is our mechanism for advancing that to Release.
Comment 17•27 days ago
|
||
Something that seems notable is that the affected Mesa driver version is almost exclusively 25.2.8.0, which presumably is shipping in Firefox snap packages currently in Ubuntu and Linux Mint and others, it seems likely this driver version has a bug, and nightly is not packaged in snap so it would get the system version of Mesa instead which is probably a different version.
Comment 18•20 days ago
•
|
||
(In reply to Brad Werth [:bradwerth] from comment #16)
I will double-check the downloadable blocklist entry. As noted by @jimb, it's weird that volume is way low on Nightly but increasing in Release, making it look like we've found a fix that isn't percolating to Release. If the fix was the blocklist entry, then the downloadable blocklist is our mechanism for advancing that to Release.
Downloadable blocklist entry is https://remote-settings.mozilla.org/v1/admin/#/buckets/staging/collections/gfx/records/aefaa076-01de-431a-81bc-e6aa2f6b84fc, which Andrew created and I approved. In theory it attempts to block MESA_THREADING for all mesa/nouveau drivers, matching the code blocklist attachment 9624088 [details]. I have two areas of uncertainty, which I hope Andrew can address:
- The link to the entry doesn't show MESA_THREADING, though it appears on the "records" view one level up. MESA_THREADING doesn't appear on the Feature dropdown at all, so this makes me feel like it isn't properly integrated into the blocklist somehow.
- It uses BLOCKED_DRIVER_VERSION with no min and a max of "155.*". I wonder if that is properly matching all driver versions. Too bad we don't have an explicit enum BLOCKED_DRIVER_ALL_VERSIONS.
Description
•