New issue
Advanced search Search tips

Issue 593995 link

Starred by 0 users

Issue metadata

Status: Verified
Owner:
Closed: Jun 2016
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Direct-leak in content::NotificationMessageFilter::OnShowPlatformNotification

Project Member Reported by ClusterFuzz, Mar 11 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6478325058371584

Fuzzer: inferno_twister
Job Type: linux_asan_content_shell_drt
Platform Id: linux

Crash Type: Direct-leak
Crash Address: 
Crash State:
  content::NotificationMessageFilter::OnShowPlatformNotification
  bool IPC::MessageT<PlatformNotificationHostMsg_Show_Meta, std::__1::tuple<int, G
  content::NotificationMessageFilter::OnMessageReceived
  

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv94XW3iRA5bvZ0zazZQkKmLi7Mv4NwttKzGQhkkYjA29Nom_-gFeKPPc7puXi77-ygmhwMVSVqS5iwWPXakJhQKQgPrGKkQKGWAdZn2Cu0X20qwG_UQ0VhTHO_56AQtkVxt7I27EVE6xrTAS08VRjUxPTzx7bIbnnujsPBbIMKtvxmPsyRg


Filer: manoranjanr

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Labels: Te-Logged
Owner: tzik@chromium.org
Status: Assigned (was: Available)
Below is the list of suspected CLs from 'Findit'.

Author: peter
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/3a3284ece57af5173175a44697df6c6d5c25c989
Time: Wed Oct 29 23:25:07 2014
The CL last changed line 141 of file notification_message_filter.cc, which is stack frame 1.

Author: mdempsky
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/8a5190449d48e06efa581390426dfa3bb6750f4c
Time: Tue Feb 09 05:41:47 2016
The CL last changed line 24 of file ipc_message_templates.h, which is stack frame 2.

Author: mdempsky
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/8a5190449d48e06efa581390426dfa3bb6750f4c
Time: Tue Feb 09 05:41:47 2016
The CL last changed line 118 of file ipc_message_templates.h, which is stack frame 3.

Author: peter
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/3a3284ece57af5173175a44697df6c6d5c25c989
Time: Wed Oct 29 23:25:07 2014
The CL last changed line 96 of file notification_message_filter.cc, which is stack frame 4.

Author: tzik
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/6ba91a9df7cb8e3fee614639c1ecb5af3f68f807
Time: Mon Feb 15 20:51:34 2016
The CL last changed line 301 of file bind_internal.h, which is stack frame 5.

Author: tzik
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/8ce65709225bac5922e6b2b80a912cf9796949b1
Time: Thu Feb 05 19:11:26 2015
The CL last changed line 351 of file bind_internal.h, which is stack frame 6.

Author: skyostil@chromium.org
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/ad8fb459e07068582588d72fd5dabdb72e70b689
Time: Thu Aug 14 14:26:09 2014
The CL last changed line 51 of file task_annotator.cc, which is stack frame 7.

tzik@, could you please look into this change (https://chromium.googlesource.com/chromium/src//+/6ba91a9df7cb8e3fee614639c1ecb5af3f68f807) if possible? Please feel free to re-assign in case if this is not your change.

Thank you!
Project Member

Comment 2 by ClusterFuzz, Apr 21 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6478325058371584

Fuzzer: inferno_twister
Job Type: linux_asan_content_shell_drt
Platform Id: linux

Crash Type: Direct-leak
Crash Address: 
Crash State:
  content::NotificationMessageFilter::OnShowPlatformNotification
  bool IPC::MessageT<PlatformNotificationHostMsg_Show_Meta, std::__1::tuple<int, G
  content::NotificationMessageFilter::OnMessageReceived
  

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv94XW3iRA5bvZ0zazZQkKmLi7Mv4NwttKzGQhkkYjA29Nom_-gFeKPPc7puXi77-ygmhwMVSVqS5iwWPXakJhQKQgPrGKkQKGWAdZn2Cu0X20qwG_UQ0VhTHO_56AQtkVxt7I27EVE6xrTAS08VRjUxPTzx7bIbnnujsPBbIMKtvxmPsyRg


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 3 by ClusterFuzz, Jun 14 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 4 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment