New issue
Advanced search Search tips

Issue 594379 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

UNKNOWN in blink::TextResourceDecoder::checkForBOM

Reported by chromium...@gmail.com, Mar 13 2016

Issue description

VERSION
Chrome Version: 51.0.2675.0 canary
Operating System: Windows 7

REPRODUCTION CASE
(watch the video)

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: Render 

eax=00000000 ebx=0003398e ecx=0cd7c000 edx=0003398d esi=0cac5050 edi=00000000
eip=0f8e1e12 esp=002ed5b0 ebp=002ed5c0 iopl=0         nv up ei pl nz na pe nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00010206
Map C:\Users\admin\AppData\Local\Google\Chrome SxS\Application\51.0.2675.0\chrome_child.dll:
  Image region 400:204c800 does not fit in mapping
*** WARNING: Unable to verify timestamp for chrome_child.dll
chrome_child!blink::TextResourceDecoder::checkForBOM+0x46:
0f8e1e12 8a19            mov     bl,byte ptr [ecx]          ds:0023:0cd7c000=??
0:000> k
  *** Stack trace for last set context - .thread/.cxr resets it
ChildEBP RetAddr  
002ed5c0 0f8e1bf8 chrome_child!blink::TextResourceDecoder::checkForBOM+0x46 [c:\b\build\slave\win\build\src\third_party\webkit\source\core\html\parser\textresourcedecoder.cpp @ 207]
002ed5f4 0fa4cfa9 chrome_child!blink::TextResourceDecoder::decode+0x22 [c:\b\build\slave\win\build\src\third_party\webkit\source\core\html\parser\textresourcedecoder.cpp @ 373]
002ed634 101dcd0a chrome_child!blink::TextResource::decodedText+0x56 [c:\b\build\slave\win\build\src\third_party\webkit\source\core\fetch\textresource.cpp @ 41]
002ed648 10206a50 chrome_child!blink::CSSStyleSheetResource::sheetText+0x49 [c:\b\build\slave\win\build\src\third_party\webkit\source\core\fetch\cssstylesheetresource.cpp @ 103]
002ed67c 03bd7980 chrome_child!blink::InspectorPageAgent::cachedResourceContent+0x138 [c:\b\build\slave\win\build\src\third_party\webkit\source\core\inspector\inspectorpageagent.cpp @ 216]
WARNING: Frame IP not in any known module. Following frames may be wrong.
002ed684 100ec152 <Unloaded_嗎ᤸ붝㩋鳳歌璜ꢗ䳶┛ᚨ揚栭視Ⳏ麈䧴쌲㙣빊㓇麈䧴 䳌꣗ᦘ₢㍄䑜៸>+0x3bd7980
002ed6b4 10151225 chrome_child!blink::InspectorResourceAgent::removedResourceFromMemoryCache+0x26 [c:\b\build\slave\win\build\src\third_party\webkit\source\core\inspector\inspectorresourceagent.cpp @ 752]
002ed6d4 002ed6fc chrome_child!blink::InspectorInstrumentation::removedResourceFromMemoryCacheImpl+0x46 [c:\b\build\slave\win\build\src\third_party\webkit\source\core\inspector\inspectorinstrumentation.cpp @ 116]
002ed6d8 0f9121b4 <Unloaded_嗎ᤸ붝㩋鳳歌璜ꢗ䳶┛ᚨ揚栭視Ⳏ麈䧴쌲㙣빊㓇麈䧴 䳌꣗ᦘ₢㍄䑜៸>+0x2ed6fc
002ed6f4 05938a28 chrome_child!blink::MemoryCache::evict+0x118 [c:\b\build\slave\win\build\src\third_party\webkit\source\core\fetch\memorycache.cpp @ 375]
002ed6fc 0fa04112 <Unloaded_嗎ᤸ붝㩋鳳歌璜ꢗ䳶┛ᚨ揚栭視Ⳏ麈䧴쌲㙣빊㓇麈䧴 䳌꣗ᦘ₢㍄䑜៸>+0x5938a28
002ed70c 058d5218 chrome_child!blink::Resource::lock+0x42 [c:\b\build\slave\win\build\src\third_party\webkit\source\core\fetch\resource.cpp @ 894]
002ed770 0f87f30b <Unloaded_嗎ᤸ붝㩋鳳歌璜ꢗ䳶┛ᚨ揚栭視Ⳏ麈䧴쌲㙣빊㓇麈䧴 䳌꣗ᦘ₢㍄䑜៸>+0x58d5218
002ed8b4 00000000 chrome_child!blink::ResourceFetcher::requestResource+0x3db [c:\b\build\slave\win\build\src\third_party\webkit\source\core\fetch\resourcefetcher.cpp @ 430]
0:000> kn

 
actual.mp4
222 KB Download
testcase.html
292 bytes View Download
23f43b9a-47c4-4575-a645-f690d8ec2704.dmp
483 KB Download
e82c85a5-af57-4962-9ac8-38ec09457af8.dmp
442 KB Download
Status: WontFix (was: Unconfirmed)
Unable to reproduce, closing.
Project Member

Comment 3 by sheriffbot@chromium.org, Jun 21 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 4 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 5 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment