New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 600664 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Email to this user bounced
Closed: Apr 2016
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug-Regression



Sign in to add a comment

Crash in blink::SpeechSynthesis::didPauseSpeaking

Project Member Reported by ClusterFuzz, Apr 5 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4548242888458240

Fuzzer: inferno_twister
Job Type: windows_syzyasan_content_shell
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 0x00000003
Crash State:
  blink::SpeechSynthesis::didPauseSpeaking
  blink::PlatformSpeechSynthesizerMock::pause
  v8::internal::FunctionCallbackArguments::Call
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=384816:384825

Minimized Testcase (0.19 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv977CbFd_6FX4bJQmwBLXzk3eD7QOaI2one7C3weFettPGpeEnW8H831VJuhyN11-TAONJDO3nvc-44Uf1l4DXPqFvO8DfSGqpztd4Sn08V21sLclDvsaHdO19kajNzl4myLJCuV0nSmzz7CZ1Ajm-MTg7iG3w
<script>

"This tests that pausing/resuming speech jobs works as expected.";
        window.internals.enableMockSpeechSynthesizer(document);
    setTimeout("speechSynthesis.pause()");
</script>


Filer: msrchandra

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: haraken@chromium.org
Labels: -Type-Bug findit-wrong Te-Logged Type-Bug-Regression
Owner: danakj@chromium.org
Status: Assigned (was: Available)
No possible suspect was found using find it, Below are the find it results:
Suspected CLs	No CL in the regression range changes the crashed files. The result is the blame information.

Author: verwaest
Component: chromium-v8
Changelist: https://chromium.googlesource.com/v8/v8.git/+/3f027300dc25b38d2c99cf35d590b09e2111ca61
Time: Thu Mar 10 15:45:28 2016
The CL last changed line 17 of file api-arguments.cc, which is stack frame 2.

Author: verwaest
Component: chromium-v8
Changelist: https://chromium.googlesource.com/v8/v8.git/+/3f027300dc25b38d2c99cf35d590b09e2111ca61
Time: Thu Mar 10 15:45:28 2016
The CL last changed line 4231 of file builtins.cc, which is stack frame 3.

Author: dcarney
Component: chromium-v8
Changelist: https://chromium.googlesource.com/v8/v8.git/+/8a78fd6d2e9fceee5ea790b6e211c006718dc655
Time: Fri Jan 23 11:22:05 2015
The CL last changed line 4248 of file builtins.cc, which is stack frame 4.

Author: vitalyr@chromium.org
Component: chromium-v8
Changelist: https://chromium.googlesource.com/v8/v8.git/+/bd06358b9340c4553b519c62ce0b3a35e6e0063a
Time: Fri Jan 15 12:25:24 2010
The CL last changed line 4245 of file builtins.cc, which is stack frame 5.

Author: jochen
Component: chromium-v8
Changelist: https://chromium.googlesource.com/v8/v8.git/+/c7aace4d43603cc03d90277e7bcf3cc538af1990
Time: Mon Nov 23 08:09:34 2015
The CL last changed line 97 of file execution.cc, which is stack frame 6.

Suspected Component: chromium

Using CodeSearch for the text "SpeechSynthesis.cpp" assigning it to the concern Dev

Suspecting Commit# 71331253d6537b9409518dec2368388c5d73cb94
Suspecting Review URL# https://codereview.chromium.org/1773813007

@dankaj -- Could you please look into the issue, pardon me if it has nothing to do with your changes and if possible please assign it to the concern Dev.
Thank You.
Um, the CL only renames methods, and wasn't in the regression range, I'm missing why this assigned to me.
Cc: -haraken@chromium.org
Owner: msrchandra@chromium.org
Labels: Needs-triage
Owner: ----
Status: Untriaged (was: Assigned)
Unable to find the exact culprit from the CL. Could some one please look into the issue and update.
Thank You.
Owner: sigbjo...@opera.com
Status: Fixed (was: Untriaged)
Project Member

Comment 7 by ClusterFuzz, Apr 7 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4548242888458240

Fuzzer: inferno_twister
Job Type: windows_syzyasan_content_shell
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 0x00000003
Crash State:
  blink::SpeechSynthesis::didPauseSpeaking
  blink::PlatformSpeechSynthesizerMock::pause
  v8::internal::FunctionCallbackArguments::Call
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=384816:384825

Minimized Testcase (0.19 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv977CbFd_6FX4bJQmwBLXzk3eD7QOaI2one7C3weFettPGpeEnW8H831VJuhyN11-TAONJDO3nvc-44Uf1l4DXPqFvO8DfSGqpztd4Sn08V21sLclDvsaHdO19kajNzl4myLJCuV0nSmzz7CZ1Ajm-MTg7iG3w
<script>

"This tests that pausing/resuming speech jobs works as expected.";
        window.internals.enableMockSpeechSynthesizer(document);
    setTimeout("speechSynthesis.pause()");
</script>


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 8 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment