New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 603321 link

Starred by 0 users

Issue metadata

Status: Duplicate
Owner:
Email to this user bounced
Closed: Apr 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in blink::PtrStorageImpl<blink::Prerender,

Project Member Reported by ClusterFuzz, Apr 13 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4779885519699968

Fuzzer: attekett_dom_fuzzer
Job Type: linux_asan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000008
Crash State:
  blink::PtrStorageImpl<blink::Prerender,
  std::__1::__tree<std::__1::__value_type<int, blink::WebPrerender>, std::__1::__m
  std::__1::__tree<std::__1::__value_type<int, blink::WebPrerender>, std::__1::__m
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=144946:145047

Minimized Testcase (3.78 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95igR76rLUMNuVFN7-XeX2f7UJ6RpgPo_Zx2j4bei1EfNJbK-pmMb-v6uSq99vCALvl4ynYHR6q787BgBS9bWFnxwOwCrWExtWitbIa4ndWi_Kb-pO1L3XfIPpTx_S70K2DMMcBIaD5PJYcSy5JyjFGzt2zaA

Additional requirements: Requires Gestures

Filer: pbommana

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: keishi@chromium.org haraken@chromium.org
Labels: M-51
Assigning the bug to "sigbjornf@opera.com" based on  issue#602227 (which was recently fixed)
Owner: sigbjo...@opera.com
Status: Assigned (was: Available)
sigbjornf@opera.com -- Could you please look into the issue as per Comment#1.
Thank You.

Comment 3 by sigbjo...@opera.com, Apr 15 2016

This is a duplicate of issue 414402, slightly different stack. I handled one problem via  issue 602227 , but evidently 414402 hides more.

Comment 4 by sigbjo...@opera.com, Apr 15 2016

Mergedinto: 414402
Status: Duplicate (was: Assigned)

Comment 5 by sigbjo...@opera.com, Apr 18 2016

Mergedinto: -414402 604325
Project Member

Comment 6 by ClusterFuzz, Apr 19 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4779885519699968

Fuzzer: attekett_dom_fuzzer
Job Type: linux_asan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000008
Crash State:
  blink::PtrStorageImpl<blink::Prerender,
  std::__1::__tree<std::__1::__value_type<int, blink::WebPrerender>, std::__1::__m
  std::__1::__tree<std::__1::__value_type<int, blink::WebPrerender>, std::__1::__m
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=144946:145047

Minimized Testcase (3.78 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95igR76rLUMNuVFN7-XeX2f7UJ6RpgPo_Zx2j4bei1EfNJbK-pmMb-v6uSq99vCALvl4ynYHR6q787BgBS9bWFnxwOwCrWExtWitbIa4ndWi_Kb-pO1L3XfIPpTx_S70K2DMMcBIaD5PJYcSy5JyjFGzt2zaA

Additional requirements: Requires Gestures

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 7 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment