Crash in blink::Node::unregisterMutationObserver |
||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6454839405445120 Fuzzer: inferno_twister_custom_bundle Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: UNKNOWN Crash Address: 0x00000008 Crash State: blink::Node::unregisterMutationObserver blink::MutationObserverRegistration::unregister blink::MutationObserver::disconnect Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=319142:319252 Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv94a1cJcdVzOIM5sjP6JRP7BeOgkaSUkZCXKUlfISbmi2E343eQWOG-yf_S-xl_k_zvO02pw2Mp5VOPKNULlbxOEHbThCqOl4DN4tvDzJqdfLwjAP6-gIcACxJPQYjqCm0OVLLqQR-rYxUDoeJ4ee4Sri7pMuQAhYhyVMrlQ5NdOAAWTt-w Additional requirements: Requires Gestures Filer: pbommana See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Mar 17 2016
,
Mar 17 2016
Removing cr- label.
,
Mar 18 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6313080140595200 Fuzzer: inferno_twister_custom_bundle Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x00000008 Crash State: blink::Node::unregisterMutationObserver blink::MutationObserverRegistration::unregister blink::MutationObserver::disconnect Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=378735:378763 Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97HfF-35Eu6IHfkuTitDUq6bCDnM5FSLaO7LjtLLRx2DacVQb-sCVimck4SlMkZMMVGs7Xj8rKhllZtGmbXlJRW_8DBjI_5DnIhl2b8iGSb2h1jTfOZmG_VA4DdgpT-EUkcAa0YWuoKHP2gXYGInB4lzkG1NE9wDB_lw10uUY6agcdiP2w Filer: ajha See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Mar 25 2016
ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6313080140595200 Fuzzer: inferno_twister_custom_bundle Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x00000008 Crash State: blink::Node::unregisterMutationObserver blink::MutationObserverRegistration::unregister blink::MutationObserver::disconnect Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=378735:378763 Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97HfF-35Eu6IHfkuTitDUq6bCDnM5FSLaO7LjtLLRx2DacVQb-sCVimck4SlMkZMMVGs7Xj8rKhllZtGmbXlJRW_8DBjI_5DnIhl2b8iGSb2h1jTfOZmG_VA4DdgpT-EUkcAa0YWuoKHP2gXYGInB4lzkG1NE9wDB_lw10uUY6agcdiP2w See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Mar 28 2016
Over to the DOM team for triage.
,
Mar 29 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5059139901849600 Fuzzer: inferno_twister_custom_bundle Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x00000008 Crash State: blink::Node::unregisterMutationObserver blink::MutationObserverRegistration::unregister blink::MutationObserver::disconnect Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=377035:377178 Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97aIhpdTL1BaJabZbsJdvVbEkv0HdL9W-nZl4-byfmmKeD225uT2Kn8VV5-2sO1wDCgCsHZU5a_EcJ_U0-qZCVkm6m2-oere4QQsM50AKjsun9QUQoSignu_X0JGOW9WY9Fswrv71-y7sfFAKdtffN39q2A3MiR_wZjZxpqqL08ThR93TM Additional requirements: Requires HTTP Filer: pucchakayala See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Mar 29 2016
,
Mar 29 2016
null deref
,
Mar 30 2016
ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5059139901849600 Fuzzer: inferno_twister_custom_bundle Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x00000008 Crash State: blink::Node::unregisterMutationObserver blink::MutationObserverRegistration::unregister blink::MutationObserver::disconnect Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=377035:377178 Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97aIhpdTL1BaJabZbsJdvVbEkv0HdL9W-nZl4-byfmmKeD225uT2Kn8VV5-2sO1wDCgCsHZU5a_EcJ_U0-qZCVkm6m2-oere4QQsM50AKjsun9QUQoSignu_X0JGOW9WY9Fswrv71-y7sfFAKdtffN39q2A3MiR_wZjZxpqqL08ThR93TM Additional requirements: Requires HTTP See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Mar 31 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4606364550168576 Fuzzer: inferno_twister Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x00000008 Crash State: blink::Node::unregisterMutationObserver blink::MutationObserverRegistration::unregister blink::MutationObserver::disconnect Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=377035:377178 Minimized Testcase (25.66 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94mk0p-d2bnRawAK815cdNz5vU3YiHrIPhElzcy7k8MVQ5-I_AmXNME53nV7lws-ujMJEHulBIZyGLt1Nx7UPT14Mp03aAT_WeJLD5C-Xy-ye3J-7MC3kuieuOndt87tTIDqqQbDlg3M1agNeTg-di0KGkfpvWmqgIKe125tQ5H-vvaks4 Filer: manoranjanr See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 1 2016
ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4606364550168576 Fuzzer: inferno_twister Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x00000008 Crash State: blink::Node::unregisterMutationObserver blink::MutationObserverRegistration::unregister blink::MutationObserver::disconnect Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=377035:377178 Minimized Testcase (25.66 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94mk0p-d2bnRawAK815cdNz5vU3YiHrIPhElzcy7k8MVQ5-I_AmXNME53nV7lws-ujMJEHulBIZyGLt1Nx7UPT14Mp03aAT_WeJLD5C-Xy-ye3J-7MC3kuieuOndt87tTIDqqQbDlg3M1agNeTg-di0KGkfpvWmqgIKe125tQ5H-vvaks4 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Apr 1 2016
ClusterFuzz has detected this issue as fixed in range 383194:384380. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6454839405445120 Fuzzer: inferno_twister_custom_bundle Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: UNKNOWN Crash Address: 0x00000008 Crash State: blink::Node::unregisterMutationObserver blink::MutationObserverRegistration::unregister blink::MutationObserver::disconnect Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=319142:319252 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=383194:384380 Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv94a1cJcdVzOIM5sjP6JRP7BeOgkaSUkZCXKUlfISbmi2E343eQWOG-yf_S-xl_k_zvO02pw2Mp5VOPKNULlbxOEHbThCqOl4DN4tvDzJqdfLwjAP6-gIcACxJPQYjqCm0OVLLqQR-rYxUDoeJ4ee4Sri7pMuQAhYhyVMrlQ5NdOAAWTt-w Additional requirements: Requires Gestures See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Apr 4 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6452923696939008 Fuzzer: inferno_twister_custom_bundle Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x00000008 Crash State: blink::Node::unregisterMutationObserver blink::MutationObserverRegistration::unregister blink::MutationObserver::disconnect Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=372998:373065 Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv951IlFDTGGlUoYmNUrt5zPfaMJhF75fHOaav2SM-MQR6lxTbIYkOZvquliQPfKA1Pxg3cJieK--xHxlDmbdfF1FJ3VCiI-J-RGtdsxq3E2Ksprxg2tqQKQAAGuz7Ovvjhdee-E7h5psnyt7yYfKyLyEuPZ4WdZSWQfonwoiaUpX4_pRZDM Filer: msrchandra See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jun 9 2016
ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6452923696939008 Fuzzer: inferno_twister_custom_bundle Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x00000008 Crash State: blink::Node::unregisterMutationObserver blink::MutationObserverRegistration::unregister blink::MutationObserver::disconnect Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=384638:384665 Minimized Testcase (1.30 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96RpbXz9qZdlZvkEqkWZnqj3KBX3oe3BHqqypzBOdS-dMoDhUOQxfZueGb1weXkWym471tpYN99m-hFngtKsaizkj_UAn7-fMggi2pCOwEuQdQhdViTVCMcsWMXF_FyzOGvb42hlU00Ngiy4ey76JnmyroSRg See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jun 9 2016
Marking 'WontFix' as per c#15. Thank you!
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||||||
►
Sign in to add a comment |
||||||||
Comment 1 by kavvaru@chromium.org
, Mar 1 2016Labels: M-49 findit-for-crash Te-Logged
Owner: e...@chromium.org
Status: Assigned (was: Available)