New issue
Advanced search Search tips

Issue 602593 link

Starred by 0 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Jul 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in blink::LayoutObject::willBeDestroyed

Project Member Reported by ClusterFuzz, Apr 12 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6339560736292864

Fuzzer: inferno_twister_custom_bundle
Job Type: linux_asan_chrome_chromeos
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  blink::LayoutObject::willBeDestroyed
  blink::LayoutBoxModelObject::willBeDestroyed
  blink::LayoutBlock::willBeDestroyed
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_chromeos&range=383194:384406

Minimized Testcase (0.30 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96dFHElwkLurlTJ7JtXe4O5nacGiiMt1LKJ4wgY_QWc8gwFOt-tJwjGSy3sj9Fd5qrDPl2hzPMNEx8AgDAb2KW1M2e0z5RZ4qrXEbNIRWx4BMVLPWxcOhYwltpDywt4R1Lf-j6DUOwA9yyXtdFtEtXdKiKkkw

Filer: tkonchada

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: flackr@chromium.org
Labels: findit-for-crash Te-Logged M-52
Owner: skyos...@chromium.org
Status: Assigned (was: Available)
CL : https://chromium.googlesource.com/chromium/src/+log/6cfa6305dc22be1489cec97f8ddcf595d75f2a75..7f57e73a09d9ad84fb64d60c6dbcaf25506fca95?pretty=fuller

Possible suspect : https://codereview.chromium.org/1850703002

Please reassign if this is not related to your change.
Project Member

Comment 2 by ClusterFuzz, Apr 13 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5938186194255872

Fuzzer: inferno_twister_custom_bundle
Job Type: linux_lsan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  blink::LayoutObject::willBeDestroyed
  blink::LayoutBoxModelObject::willBeDestroyed
  blink::LayoutPart::willBeDestroyed
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=209699:209703

Minimized Testcase (6.58 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96jcMmR6J8VHNSmut83d8TqQg7UzRKyTlwSYAybgYfpmvxGZuyQORvfalAGtbFwKQH5IutaIhstS3DZN3-M8L8nawegTccQFsZLnf4SFYOQvaXUs7_DivaoP14SZU3SiYQKAsOQanniD52dwXnx57Jc-y_kpw

Additional requirements: Requires HTTP

Filer: ligimole

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

Comment 3 by flackr@chromium.org, Apr 13 2016

This change seems unlikely to have caused the failure as it's a revert of my CL which introduced a crash. This crash looks unrelated as well.
Cc: skyos...@chromium.org
Owner: ----
Status: Available (was: Assigned)
Right, sorry, no idea what's going on here.
Project Member

Comment 5 by sheriffbot@chromium.org, Jun 1 2016

Labels: -M-52 M-53 MovedFrom-52
Moving this nonessential bug to the next milestone.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 6 by ClusterFuzz, Jun 9 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5938186194255872

Fuzzer: inferno_twister_custom_bundle
Job Type: linux_lsan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  blink::LayoutObject::willBeDestroyed
  blink::LayoutText::willBeDestroyed
  blink::LayoutObject::destroy
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=383194:384397

Minimized Testcase (0.15 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv94G2RX6DWVl3qsVjnhwFi8Qxx6z_KK-qFwkRlhhl-piLOl4-rs29-lFEL6HmxssG8gcXIbJsi5MCR6slLVEXhnls4W67nZb1837a7XGGoVMhKWf3hjs5VFdnJRvkD8pooLDscQilitswnrb8z9-tRpst_5EFA
    }<style>
* { background-clip: content-box; content: url("chrome://does-not-exist")");</style><script>
setTimeout("window.location.reload();");
</script>


Additional requirements: Requires HTTP

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 7 by ClusterFuzz, Jun 28 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6339560736292864

Fuzzer: inferno_twister_custom_bundle
Job Type: linux_asan_chrome_chromeos
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  blink::LayoutObject::willBeDestroyed
  blink::LayoutBoxModelObject::willBeDestroyed
  blink::LayoutBlock::willBeDestroyed
  

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv950KlzbHqbRCz-stBevVMFAwkVaKYyiPghU1t4nRTHsma_GrgMADRZSe4Oy4hNbIr8xeNLnOyqx_PTba8Le-5iMlRUiBcQXNRIoDffB7AWeVNwyvBAAFbmtik0DG9T3vcekqMEs_vtvdA_WsyibmUkNcxDgxKh-wQOl55WU-dXcZnx3mq4?testcase_id=6339560736292864


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Components: Blink>Layout
Status: Untriaged (was: Available)

Comment 9 by e...@chromium.org, Jul 6 2016

Status: WontFix (was: Untriaged)
Marking as WontFix as per comment 6 and 7.
Project Member

Comment 10 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment