protonscr

steamwebhelper gobbles up memory

steamclosed Big PictureDistro Family: SteamOSWeb
ValveSoftware/steam-for-linux#5108 · opened 2017-07-31 by ardje · updated 2019-07-18 · 9 comments · github
Aardje 2017-07-31 github

Your system information

  • Steam client version (build number or date): 1501267201 (2017-07-28)
  • Distribution (e.g. Ubuntu): steamos
  • Opted into Steam client beta?: [Yes/No] Yes
  • Have you checked for system updates?: [Yes/No] Yes

Please describe your issue in as much detail as possible:

[09:36] <ard>   PID USER      PR  NI    VIRT    RES    SHR S  %CPU %MEM     TIME+ COMMAND
[09:36] <ard> 10739 steam     20   0 32.877g 0.015t   1900 S  44.4 95.9   1:37.93 steamwebhelper

That's a whopping 32GB virt and 15GB RSS on a 16GB system.
And a few moments later from dmesg:

ERROR: ld.so: object '/usr/lib/i386-linux-gnu/libmodeswitch_inhibitor.so' from LD_PRELOAD cannot be preloaded (wrong ELF class: ELFCLASS32): ignored.
[0731/093615.122630:FATAL:memory_linux.cc(35)] Out of memory.
[0731/093617.262610:WARNING:x11_util.cc(1364)] X error received: serial 104650, error_code 3 (BadWindow (invalid Window parameter)), request_code 4, minor_code 0 (X_DestroyWindow)
ERROR: ld.so: object '/usr/lib/i386-linux-gnu/libmodeswitch_inhibitor.so' from LD_PRELOAD cannot be preloaded (wrong ELF class: ELFCLASS32): ignored.

So what did I do?
I just turned on the monitor, and tried to play a tune from http://www.mix.dj . First time it shows an empty page, second time I got the page, and them my controls went all clickety (usually means the steam controller acts like a mouse), so I decided to go into the config to "load" my less clickety settings, and then the system "froze" until the OOM.

Is this reproducable...? Well, the not getting any web pages seems to reproducable. Let me put that in time:

  1. a few releases ago we had corruption of the web pages. That got fixed.
  2. When that got fixed, playing any of the videos got broken (I don't know if that is related).
  3. with this release I could play the videos again, but every time I (try to) open a web page it either shows nothing, or I need to open a second tab or third tab which usually also don't work. Or I need to reboot and 25% chance the browser works as expected.

The dump is uploaded as:

Mon Jul 31 07:41:38 2017 GMT: file ''/tmp/dumps/assert_20170731094135_42.dmp'', upload yes: ''CrashID=bp-1979e0f0-6f47-4e26-bce7-27d662170731''

graph

This is the memory graph, it's the last spike that you see that was the OOM. So something just makes it go OOM in a matter of minutes.

PS: sorry about the graph, see next comment. It seems it is SVG and not a PNG.

Aardje 2017-07-31 github

graph
Arrgh.... That's a days graph.... I can pm you the stats server for my steamos, I can also give you root access to the steam machine iff you have ipv6 (for any future test case you want to try out, you know where to find me on IRC ;-) ).

Aardje 2017-08-01 github

Ok, less than an hour ago I turned on the steam machine using the controller.
At this moment I went to web (left shoulder), last pages (2x left trigger) and selected mix.dj
From that moment on the page "freezes", but from the terminal I can see steamwebhelper explode until it ooms. It got even more than 35G virt today, oh wait: swap+memory is about 45G. Well, it's a nice way to force everything unnecessary into swap 8-D.
I've noticed yesterday that after the OOM, the build-in browser worked.
I've now let it just crash on the first page, and I got an "Oops","The page you were viewing encountered an error and was terminated. Click here to reload".

Tomorrow I will test an internal plain text page after a reboot and see how that goes. I never figured it was the browser waiting on the webhelper, I always thought the renderer crashed immediately.

Aardje 2017-08-01 github

Couldn't resist: I rebooted.
Went to plain text->ok
Google (not plain text anymore)->ok
Went to mix.dj > OOM

This is a snapshot of an strace:

[pid  1637] <... epoll_wait resumed> {{EPOLLIN, {u32=28, u64=28}}}, 32, -1) = 1
[pid  1637] recvmsg(28, {msg_name(0)=NULL, msg_iov(1)=[{"\300\0\0\0\20\0\1\0\0\0\0\0\0\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0"..., 4096}], msg_controllen=0, msg_flags=0}, MSG_DONTWAIT) = 192
[pid  1637] gettid()                    = 1637
[pid  1637] gettid()                    = 1637
[pid  1637] epoll_wait(23, {}, 32, 0)   = 0
[pid  1637] epoll_wait(23, {}, 32, 0)   = 0
[pid  1637] epoll_wait(23,  <unfinished ...>
[pid  1639] mmap(0x2edaafb38000, 1048576, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2edaafb38000
[pid  1639] madvise(0x2edaafb38000, 1048576, MADV_DONTNEED) = 0
[pid  1639] mmap(0x2edaafc38000, 1048576, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2edaafc38000
[pid  1639] madvise(0x2edaafc38000, 1048576, MADV_DONTNEED) = 0
[pid  1639] mmap(0x2edaafd38000, 1048576, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2edaafd38000
[pid  1639] madvise(0x2edaafd38000, 1048576, MADV_DONTNEED) = 0
[pid  1639] mmap(0x2edaafe38000, 1048576, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2edaafe38000
[pid  1639] madvise(0x2edaafe38000, 1048576, MADV_DONTNEED) = 0
[pid  1639] mmap(0x2edaaff38000, 1048576, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2edaaff38000
[pid  1639] mmap(0x2edab0038000, 32768, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2edab0038000
[pid  1639] madvise(0x2edaaff38000, 1048576, MADV_DONTNEED) = 0

This is the only thing I see from strace, and before I noticed fd 28, I was too late.
Anyway: that's it: recvmsg, gettid (pid=1635), and then mmap some extra anonymous memory (malloc?), until swap+mem is full, then OOM.
I assume fd 28 is just some maintenance fd, like timers, epoll or anything.
The webhelper is probably doing something without bounds checking.

Curious... I just got it to trigger a second time in the same browsing session:
Early in the strace it uses futex a lot:

root@steamos:~# strace -c -f -p 1892
Process 1892 attached with 11 threads
Process 1960 attached
Process 1961 attached
Process 1962 attached
% time     seconds  usecs/call     calls    errors syscall
------ ----------- ----------- --------- --------- ----------------
 63.51   17.934942        1506     11912      5919 futex
 27.30    7.708794         574     13424           epoll_wait
  8.23    2.324906     2324906         1         1 restart_syscall
  0.66    0.187381           1    170386           gettid
  0.16    0.046016           3     15820           mmap
  0.07    0.020270           5      4488           recvmsg
  0.05    0.013372           1     13664           madvise
  0.01    0.002813           2      1371           mprotect
  0.00    0.000134          22         6         6 stat
  0.00    0.000061          20         3           clone
  0.00    0.000046          23         2           write
  0.00    0.000028           9         3           setpriority
  0.00    0.000023           8         3           set_robust_list
  0.00    0.000011          11         1           munmap
  0.00    0.000007           2         3           prctl
  0.00    0.000003           3         1           tgkill
  0.00    0.000001           1         1           rt_sigprocmask
  0.00    0.000000           0         2           close
  0.00    0.000000           0         1           sendmsg
  0.00    0.000000           0         1           socketpair
------ ----------- ----------- --------- --------- ----------------
100.00   28.238808                231093      5926 total

And yes, the secret to the OOM is somewhere to be found on the http://www.mix.dj pages.
I recommend them if you like house, I need it to get my brain going.

Aardje 2017-08-02 github

Correction: plain text can lead to a dump too.
What I did notice:
First tab open -> webhelper goes beserk
Second tab open:we let the webhelper go beserk on the first page -> opens
after that it's just waiting until the first tab crashes and we have to close that tab. The second tab doesn't seem to use it somehow.

Ssvanheulen 2017-08-03 github

I'm having the same issue on Arch Linux.

Aardje 2017-08-14 github

I failed to mention that with the new steam client it seems to not gobble up memory anymore. At least not for me.
@svanheulen can you confirm that too?
Not only does it not gobble up memory anymore, but I can also use the crunchyroll beta html player \0/ (totally unrelated though) .

Ssvanheulen 2017-08-14 github

Yeah, it seems to be fixed now.

Aardje 2017-08-21 github

Closing since it was fixed with the new client.

Sstevenroose 2018-11-28 github

I still have this. I'm running the steam Arch package from multilib.

Nothing extracted yet.