New issue
Advanced search Search tips

Issue 593310 link

Starred by 0 users

Issue metadata

Status: Duplicate
Merged: issue 592831
Owner:
Closed: Mar 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug



Sign in to add a comment

Crash in blink::WebURLRequest::url

Project Member Reported by ClusterFuzz, Mar 9 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5086496211599360

Fuzzer: inferno_layout_test_unmodified
Job Type: windows_syzyasan_content_shell
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 0x00000007
Crash State:
  blink::WebURLRequest::url
  content::MojoContextState::OnFetchModuleComplete
  base::internal::Invoker<base::IndexSequence<0,1>,base::internal::BindState<base:
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=379903:379959

Minimized Testcase (21.53 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96NT-yYX--ZGPn9zBKfPN-Ual_kICj8LLEaMb1L4lNBv0phj_TlRmd4rifjZvLWL49L8lGDnDvGu_1f960jy5ZfgUYpL8c3ycDG_YKCQDQvBsep0a_5qyum-zdlJvRJOiyGv4Q5ce-uET3_IwtmDZhtV-XbeTlEH7uQpLjqMRlp_6KVTEA

Filer: nyerramilli

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: nyerramilli@chromium.org
Labels: findit-wrong Te-Logged
Owner: sa...@chromium.org
Status: Assigned (was: Available)
providing Find it info for internal purpose:

	No CL in the regression range changes the crashed files. The result is the blame information.

Author: sammc
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/afd813ed4b6ce7fbaef2ed9dc39802bcd5587c79
Time: Mon Nov 30 01:46:46 2015
The CL last changed line 183 of file mojo_context_state.cc, which is stack frame 1.

Author: tzik
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/6ba91a9df7cb8e3fee614639c1ecb5af3f68f807
Time: Mon Feb 15 20:51:34 2016
The CL last changed line 181 of file bind_internal.h, which is stack frame 2.

Author: tzik
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/6ba91a9df7cb8e3fee614639c1ecb5af3f68f807
Time: Mon Feb 15 20:51:34 2016
The CL last changed line 301 of file bind_internal.h, which is stack frame 3.

Author: ajwong@chromium.org
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/fccef1559e02b001c69a0d35ad960e37dcbfd650
Time: Mon Nov 28 22:13:54 2011
The CL last changed line 355 of file bind_internal.h, which is stack frame 4.

Author: tzik
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/c87149e666acfe39d49d7f30a5fd9acc7ef085ea
Time: Thu Nov 20 01:08:20 2014
The CL last changed line 394 of file callback.h, which is stack frame 5.

Author: mlamouri
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/b16c57177635dcc6d88f6eae2eee41af1acf5f58
Time: Sat Sep 13 12:46:59 2014
The CL last changed line 145 of file resource_fetcher_impl.cc, which is stack frame 6.

Suspected Component: chromium

this might be dupe of https://bugs.chromium.org/p/chromium/issues/detail?id=592831
the first line of Crash stack not matched hence logged this issue
blink::WebURLRequest::url

sammc@, could you please check and suggest.

Comment 2 by sa...@chromium.org, Mar 13 2016

Mergedinto: 592831
Status: Duplicate (was: Assigned)
Project Member

Comment 3 by ClusterFuzz, Mar 14 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5086496211599360

Fuzzer: inferno_layout_test_unmodified
Job Type: windows_syzyasan_content_shell
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 0x00000007
Crash State:
  blink::WebURLRequest::url
  content::MojoContextState::OnFetchModuleComplete
  base::internal::Invoker<base::IndexSequence<0,1>,base::internal::BindState<base:
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=379903:379959

Minimized Testcase (21.53 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96NT-yYX--ZGPn9zBKfPN-Ual_kICj8LLEaMb1L4lNBv0phj_TlRmd4rifjZvLWL49L8lGDnDvGu_1f960jy5ZfgUYpL8c3ycDG_YKCQDQvBsep0a_5qyum-zdlJvRJOiyGv4Q5ce-uET3_IwtmDZhtV-XbeTlEH7uQpLjqMRlp_6KVTEA

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 4 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment