New issue
Advanced search Search tips

Issue 592831 link

Starred by 0 users

Issue metadata

Status: Fixed
Owner:
Closed: Mar 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug



Sign in to add a comment

Crash in blink::WebURLResponse::url

Project Member Reported by ClusterFuzz, Mar 8 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5128312824791040

Fuzzer: inferno_layout_test_unmodified
Job Type: windows_syzyasan_content_shell
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 0x00000007
Crash State:
  blink::WebURLResponse::url
  content::MojoContextState::OnFetchModuleComplete
  base::internal::Invoker<base::IndexSequence<0,1>,base::internal::BindState<base:
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=379500:379506

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv96y51NiK_UiIrtSKT4RoxLVOKlmSzF9LiVYxDs5XraJbCFCDLtGBuMsPNg8LxdnDRKPewuA-WpR7yBkxoool3yXs-gdMTTHorZsJImgRCo-ZggYxNCEBreiGSvc_g2i1eVxSfSAMqiqsf4WrSDthqUqY2VFijhUwvERv8ub1Qbo6_hEzeo


Filer: pucchakayala

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Labels: findit-for-crash M-51 Te-Logged
Owner: tzik@chromium.org
Status: Assigned (was: Available)
Suspected CLs	No CL in the regression range changes the crashed files. The result is the blame information.

Author: sammc
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/afd813ed4b6ce7fbaef2ed9dc39802bcd5587c79
Time: Mon Nov 30 01:46:46 2015
The CL last changed line 183 of file mojo_context_state.cc, which is stack frame 1.

Author: tzik
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/6ba91a9df7cb8e3fee614639c1ecb5af3f68f807
Time: Mon Feb 15 20:51:34 2016
The CL last changed line 181 of file bind_internal.h, which is stack frame 2.

Author: tzik
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/6ba91a9df7cb8e3fee614639c1ecb5af3f68f807
Time: Mon Feb 15 20:51:34 2016
The CL last changed line 301 of file bind_internal.h, which is stack frame 3.

Author: ajwong@chromium.org
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/fccef1559e02b001c69a0d35ad960e37dcbfd650
Time: Mon Nov 28 22:13:54 2011
The CL last changed line 355 of file bind_internal.h, which is stack frame 4.

Author: tzik
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/c87149e666acfe39d49d7f30a5fd9acc7ef085ea
Time: Thu Nov 20 01:08:20 2014
The CL last changed line 394 of file callback.h, which is stack frame 5.

Author: mlamouri
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/b16c57177635dcc6d88f6eae2eee41af1acf5f58
Time: Sat Sep 13 12:46:59 2014
The CL last changed line 145 of file resource_fetcher_impl.cc, which is stack frame 6.

Suspected Component: chromium
Project Member

Comment 2 by ClusterFuzz, Mar 8 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6503648191840256

Fuzzer: inferno_layout_test_unmodified
Job Type: windows_syzyasan_content_shell
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 0x00000007
Crash State:
  blink::WebURLRequest::url
  content::MojoContextState::OnFetchModuleComplete
  base::internal::Invoker<base::IndexSequence<0,1>,base::internal::BindState<base:
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=379469:379486

Minimized Testcase (27.12 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94aiQIDk3uHfr3pEBcW5WzpPrWZmJ_PDv92WWv5DpW68BlMOc6ycfAzKggLOHyYP9dF4oPVuXckJxwWKBGWvk8q5tP9QHT5Iw8Dbj6mZBhtmyNZecsJ8SdVJRJi9LjRD7mhcWAILzZucL5BJJgKT90SjBzRNWbrxb37gaNpnI8K4eQb3_c

Filer: pucchakayala

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Project Member

Comment 3 by ClusterFuzz, Mar 8 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6503648191840256

Fuzzer: inferno_layout_test_unmodified
Job Type: windows_syzyasan_content_shell
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 0x00000007
Crash State:
  blink::WebURLRequest::url
  content::MojoContextState::OnFetchModuleComplete
  base::internal::Invoker<base::IndexSequence<0,1>,base::internal::BindState<base:
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=379469:379486

Minimized Testcase (27.12 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94aiQIDk3uHfr3pEBcW5WzpPrWZmJ_PDv92WWv5DpW68BlMOc6ycfAzKggLOHyYP9dF4oPVuXckJxwWKBGWvk8q5tP9QHT5Iw8Dbj6mZBhtmyNZecsJ8SdVJRJi9LjRD7mhcWAILzZucL5BJJgKT90SjBzRNWbrxb37gaNpnI8K4eQb3_c

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Comment 4 by tzik@chromium.org, Mar 8 2016

Cc: tzik@chromium.org
Owner: sa...@chromium.org
sammc: Could you handle this?
This seems due to a null |response| at mojo_context_state.cc [1]. Since it can be null on error case, we need an error handling here.

[1] https://chromium.googlesource.com/chromium/src/+/c1bb9d9096de137378cb1029021aed40fcbf76e4/content/renderer/mojo_context_state.cc#183
Project Member

Comment 5 by ClusterFuzz, Mar 9 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5128312824791040

Fuzzer: inferno_layout_test_unmodified
Job Type: windows_syzyasan_content_shell
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 0x00000007
Crash State:
  blink::WebURLResponse::url
  content::MojoContextState::OnFetchModuleComplete
  base::internal::Invoker<base::IndexSequence<0,1>,base::internal::BindState<base:
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=379500:379506

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv96y51NiK_UiIrtSKT4RoxLVOKlmSzF9LiVYxDs5XraJbCFCDLtGBuMsPNg8LxdnDRKPewuA-WpR7yBkxoool3yXs-gdMTTHorZsJImgRCo-ZggYxNCEBreiGSvc_g2i1eVxSfSAMqiqsf4WrSDthqUqY2VFijhUwvERv8ub1Qbo6_hEzeo


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 6 by bugdroid1@chromium.org, Mar 11 2016

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/2eb97bdbc5ebc7fec94c53010b064c677e4cab8f

commit 2eb97bdbc5ebc7fec94c53010b064c677e4cab8f
Author: sammc <sammc@chromium.org>
Date: Fri Mar 11 05:24:39 2016

Handle JS mojo module fetch failures gracefully.

Currently, if the fetch of the source for a JS mojo module fails, the
requesting renderer crashes. With this CL, it logs an error instead.

BUG= 592831 

Review URL: https://codereview.chromium.org/1776263002

Cr-Commit-Position: refs/heads/master@{#380528}

[modify] https://crrev.com/2eb97bdbc5ebc7fec94c53010b064c677e4cab8f/content/renderer/mojo_context_state.cc
[modify] https://crrev.com/2eb97bdbc5ebc7fec94c53010b064c677e4cab8f/content/renderer/mojo_context_state.h

Project Member

Comment 7 by ClusterFuzz, Mar 11 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4874772107755520

Fuzzer: inferno_layout_test_unmodified
Job Type: windows_syzyasan_content_shell
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 0x00000007
Crash State:
  blink::WebURLResponse::url
  content::MojoContextState::OnFetchModuleComplete
  base::internal::Invoker<base::IndexSequence<0,1>,base::internal::BindState<base:
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=380397:380402

Minimized Testcase (24.31 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96kW2Ndin9Vdmg8LH2SFRsYxvYAGRkMkaTOHVPsyeFpso6npz2IiBx-90lIBWL00Cje3e39LBLIDyEcnJsTKbYy2pb8W6Yb57ZwQWichbgD3YMHg-tvTFA6eHRKyd3ivLUNiUrbuQSggjKrPWSuO7wSlTFB3vc45TAJq2Yn_YEaYRfhbW0

Additional requirements: Requires Gestures

Filer: nyerramilli

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

Comment 8 by sa...@chromium.org, Mar 13 2016

Cc: nyerramilli@chromium.org sa...@chromium.org
 Issue 593310  has been merged into this issue.

Comment 9 by sa...@chromium.org, Mar 13 2016

Status: Fixed (was: Assigned)
Project Member

Comment 10 by ClusterFuzz, Mar 17 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4874772107755520

Fuzzer: inferno_layout_test_unmodified
Job Type: windows_syzyasan_content_shell
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 0x00000007
Crash State:
  blink::WebURLResponse::url
  content::MojoContextState::OnFetchModuleComplete
  base::internal::Invoker<base::IndexSequence<0,1>,base::internal::BindState<base:
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=380397:380402

Minimized Testcase (24.31 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96kW2Ndin9Vdmg8LH2SFRsYxvYAGRkMkaTOHVPsyeFpso6npz2IiBx-90lIBWL00Cje3e39LBLIDyEcnJsTKbYy2pb8W6Yb57ZwQWichbgD3YMHg-tvTFA6eHRKyd3ivLUNiUrbuQSggjKrPWSuO7wSlTFB3vc45TAJq2Yn_YEaYRfhbW0

Additional requirements: Requires Gestures

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 11 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment