New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 590910 link

Starred by 3 users

Issue metadata

Status: WontFix
Owner:
Last visit > 30 days ago
Closed: Jun 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in blink::Node::unregisterMutationObserver

Project Member Reported by ClusterFuzz, Feb 29 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6454839405445120

Fuzzer: inferno_twister_custom_bundle
Job Type: linux_asan_chrome_v8_arm
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x00000008
Crash State:
  blink::Node::unregisterMutationObserver
  blink::MutationObserverRegistration::unregister
  blink::MutationObserver::disconnect
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=319142:319252

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv94a1cJcdVzOIM5sjP6JRP7BeOgkaSUkZCXKUlfISbmi2E343eQWOG-yf_S-xl_k_zvO02pw2Mp5VOPKNULlbxOEHbThCqOl4DN4tvDzJqdfLwjAP6-gIcACxJPQYjqCm0OVLLqQR-rYxUDoeJ4ee4Sri7pMuQAhYhyVMrlQ5NdOAAWTt-w


Additional requirements: Requires Gestures

Filer: pbommana

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: kavvaru@chromium.org
Labels: M-49 findit-for-crash Te-Logged
Owner: e...@chromium.org
Status: Assigned (was: Available)
No CL in the regression range changes the crashed files. The result is the blame information.

Author: mjs@apple.com
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/554c7634cddfec7925865257d362fa718c34ac3a
Time: Thu May 06 22:41:15 2010
The CL last changed line 740 of file Node.h, which is stack frame 0.

Author: eae@chromium.org
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/6a5c28eb68ffad0155a7b86e5394aa10ca6af96a
Time: Thu Dec 06 21:41:27 2012
The CL last changed line 774 of file Node.h, which is stack frame 1.

Author: rniwa@webkit.org
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/3dc9bec08c90cef49b3199f606a59f824cbb557d
Time: Mon Jan 14 23:57:39 2013
The CL last changed line 1905 of file Node.cpp, which is stack frame 2.

Author: kenneth.r.christiansen@intel.com
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/cc604a057cdae70220ad0c36095d5decbbd27980
Time: Thu Oct 23 12:24:00 2014
The CL last changed line 1972 of file Node.cpp, which is stack frame 3.

Author: sigbjornf@opera.com
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/8d3c0bd9ce51f5dcfc0807fb0c3775ed15d6675e
Time: Thu May 08 08:09:06 2014
The CL last changed line 110 of file MutationObserverRegistration.cpp, which is stack frame 4.

Author: kouhei@chromium.org
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/8d8f2e1e111607fec4c8aa3885e3f55a0b2fb3f3
Time: Fri Mar 27 07:16:44 2015
The CL last changed line 151 of file MutationObserver.cpp, which is stack frame 5.

Suspected Component: chromium-blink
Suspected Cr- Label: Cr-Blink-DOM
================
Above is the CL from findit and the changes made to file "Node.h" from the frame # 1  is more related to it.

eae@: Could you please re-assign to an appropriate dev person if its not related to your change,else please help us in finding the appropriate owner for this issue.

Thanks,
Components: Blink>DOM
Labels: -Cr-Blink-DOM
Removing cr- label.
Project Member

Comment 4 by ClusterFuzz, Mar 18 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6313080140595200

Fuzzer: inferno_twister_custom_bundle
Job Type: linux_asan_chrome_v8_arm
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00000008
Crash State:
  blink::Node::unregisterMutationObserver
  blink::MutationObserverRegistration::unregister
  blink::MutationObserver::disconnect
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=378735:378763

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97HfF-35Eu6IHfkuTitDUq6bCDnM5FSLaO7LjtLLRx2DacVQb-sCVimck4SlMkZMMVGs7Xj8rKhllZtGmbXlJRW_8DBjI_5DnIhl2b8iGSb2h1jTfOZmG_VA4DdgpT-EUkcAa0YWuoKHP2gXYGInB4lzkG1NE9wDB_lw10uUY6agcdiP2w


Filer: ajha

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Project Member

Comment 5 by ClusterFuzz, Mar 25 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6313080140595200

Fuzzer: inferno_twister_custom_bundle
Job Type: linux_asan_chrome_v8_arm
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00000008
Crash State:
  blink::Node::unregisterMutationObserver
  blink::MutationObserverRegistration::unregister
  blink::MutationObserver::disconnect
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=378735:378763

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97HfF-35Eu6IHfkuTitDUq6bCDnM5FSLaO7LjtLLRx2DacVQb-sCVimck4SlMkZMMVGs7Xj8rKhllZtGmbXlJRW_8DBjI_5DnIhl2b8iGSb2h1jTfOZmG_VA4DdgpT-EUkcAa0YWuoKHP2gXYGInB4lzkG1NE9wDB_lw10uUY6agcdiP2w


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Comment 6 by e...@chromium.org, Mar 28 2016

Owner: ----
Status: Untriaged (was: Assigned)
Over to the DOM team for triage.
Project Member

Comment 7 by ClusterFuzz, Mar 29 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5059139901849600

Fuzzer: inferno_twister_custom_bundle
Job Type: linux_asan_chrome_v8_arm
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00000008
Crash State:
  blink::Node::unregisterMutationObserver
  blink::MutationObserverRegistration::unregister
  blink::MutationObserver::disconnect
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=377035:377178

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97aIhpdTL1BaJabZbsJdvVbEkv0HdL9W-nZl4-byfmmKeD225uT2Kn8VV5-2sO1wDCgCsHZU5a_EcJ_U0-qZCVkm6m2-oere4QQsM50AKjsun9QUQoSignu_X0JGOW9WY9Fswrv71-y7sfFAKdtffN39q2A3MiR_wZjZxpqqL08ThR93TM


Additional requirements: Requires HTTP

Filer: pucchakayala

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Labels: -M-49 M-50
Owner: dominicc@chromium.org
Status: Available (was: Untriaged)
null deref
Project Member

Comment 10 by ClusterFuzz, Mar 30 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5059139901849600

Fuzzer: inferno_twister_custom_bundle
Job Type: linux_asan_chrome_v8_arm
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00000008
Crash State:
  blink::Node::unregisterMutationObserver
  blink::MutationObserverRegistration::unregister
  blink::MutationObserver::disconnect
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=377035:377178

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97aIhpdTL1BaJabZbsJdvVbEkv0HdL9W-nZl4-byfmmKeD225uT2Kn8VV5-2sO1wDCgCsHZU5a_EcJ_U0-qZCVkm6m2-oere4QQsM50AKjsun9QUQoSignu_X0JGOW9WY9Fswrv71-y7sfFAKdtffN39q2A3MiR_wZjZxpqqL08ThR93TM


Additional requirements: Requires HTTP

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 11 by ClusterFuzz, Mar 31 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4606364550168576

Fuzzer: inferno_twister
Job Type: linux_asan_chrome_v8_arm
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00000008
Crash State:
  blink::Node::unregisterMutationObserver
  blink::MutationObserverRegistration::unregister
  blink::MutationObserver::disconnect
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=377035:377178

Minimized Testcase (25.66 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94mk0p-d2bnRawAK815cdNz5vU3YiHrIPhElzcy7k8MVQ5-I_AmXNME53nV7lws-ujMJEHulBIZyGLt1Nx7UPT14Mp03aAT_WeJLD5C-Xy-ye3J-7MC3kuieuOndt87tTIDqqQbDlg3M1agNeTg-di0KGkfpvWmqgIKe125tQ5H-vvaks4

Filer: manoranjanr

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Project Member

Comment 12 by ClusterFuzz, Apr 1 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4606364550168576

Fuzzer: inferno_twister
Job Type: linux_asan_chrome_v8_arm
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00000008
Crash State:
  blink::Node::unregisterMutationObserver
  blink::MutationObserverRegistration::unregister
  blink::MutationObserver::disconnect
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=377035:377178

Minimized Testcase (25.66 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94mk0p-d2bnRawAK815cdNz5vU3YiHrIPhElzcy7k8MVQ5-I_AmXNME53nV7lws-ujMJEHulBIZyGLt1Nx7UPT14Mp03aAT_WeJLD5C-Xy-ye3J-7MC3kuieuOndt87tTIDqqQbDlg3M1agNeTg-di0KGkfpvWmqgIKe125tQ5H-vvaks4

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 13 by ClusterFuzz, Apr 1 2016

ClusterFuzz has detected this issue as fixed in range 383194:384380.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6454839405445120

Fuzzer: inferno_twister_custom_bundle
Job Type: linux_asan_chrome_v8_arm
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x00000008
Crash State:
  blink::Node::unregisterMutationObserver
  blink::MutationObserverRegistration::unregister
  blink::MutationObserver::disconnect
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=319142:319252
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=383194:384380

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv94a1cJcdVzOIM5sjP6JRP7BeOgkaSUkZCXKUlfISbmi2E343eQWOG-yf_S-xl_k_zvO02pw2Mp5VOPKNULlbxOEHbThCqOl4DN4tvDzJqdfLwjAP6-gIcACxJPQYjqCm0OVLLqQR-rYxUDoeJ4ee4Sri7pMuQAhYhyVMrlQ5NdOAAWTt-w


Additional requirements: Requires Gestures

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 14 by ClusterFuzz, Apr 4 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6452923696939008

Fuzzer: inferno_twister_custom_bundle
Job Type: linux_asan_chrome_v8_arm
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00000008
Crash State:
  blink::Node::unregisterMutationObserver
  blink::MutationObserverRegistration::unregister
  blink::MutationObserver::disconnect
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=372998:373065

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv951IlFDTGGlUoYmNUrt5zPfaMJhF75fHOaav2SM-MQR6lxTbIYkOZvquliQPfKA1Pxg3cJieK--xHxlDmbdfF1FJ3VCiI-J-RGtdsxq3E2Ksprxg2tqQKQAAGuz7Ovvjhdee-E7h5psnyt7yYfKyLyEuPZ4WdZSWQfonwoiaUpX4_pRZDM


Filer: msrchandra

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Project Member

Comment 15 by ClusterFuzz, Jun 9 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6452923696939008

Fuzzer: inferno_twister_custom_bundle
Job Type: linux_asan_chrome_v8_arm
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00000008
Crash State:
  blink::Node::unregisterMutationObserver
  blink::MutationObserverRegistration::unregister
  blink::MutationObserver::disconnect
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=384638:384665

Minimized Testcase (1.30 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96RpbXz9qZdlZvkEqkWZnqj3KBX3oe3BHqqypzBOdS-dMoDhUOQxfZueGb1weXkWym471tpYN99m-hFngtKsaizkj_UAn7-fMggi2pCOwEuQdQhdViTVCMcsWMXF_FyzOGvb42hlU00Ngiy4ey76JnmyroSRg

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Status: WontFix (was: Available)
Marking 'WontFix' as per c#15.

Thank you!
Project Member

Comment 17 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment