New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 613064 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jun 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug-Regression



Sign in to add a comment

Crash in blink::DocumentMarkerController::markersInRange

Project Member Reported by ClusterFuzz, May 19 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4728984880807936

Fuzzer: bj_broddelwerk
Job Type: linux_asan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000010
Crash State:
  blink::DocumentMarkerController::markersInRange
  blink::SpellCheckRequest::create
  blink::SpellChecker::chunkAndMarkAllMisspellingsAndBadGrammar
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=144946:145047

Minimized Testcase (4.55 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96pcI7F7MY78zB71hGarPXI7lnkfxYX_BSd67PssknMCIX35aJGw7-H6jqpR2u5cpliqee9GYQFsTAPlrLJRgIsV573wCOY12phaktCpLaHWlDVUVkoOzgb426MB8Y8_EmBtb6bp0mt8IcZYBrlWbgNRpS2CA

Filer: ranjitkan

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: ranjitkan@chromium.org
Components: Tools>Test>FindIt>CorrectResult
Labels: -Pri-1 -Type-Bug findit-for-crash Te-Logged M-52 Pri-2 Type-Bug-Regression
Owner: yosin@chromium.org
Author: yosin@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/28e6e02ece333238e40f3b3de020c392b0dcfc9d
Time: Wed Jul 15 22:21:51 2015
The CL last changed line 460 of file DocumentMarkerController.cpp, which is stack frame 6.

@yosin: Assigning to you, request you to please take a look into it. Please help us to reassign if not with respect to your change.

Comment 2 by yosin@chromium.org, May 23 2016

Components: Blink>Editing>Command
Owner: ----
Could not reproduce with ToT
Project Member

Comment 3 by sheriffbot@chromium.org, Jun 1 2016

Labels: -M-52 M-53 MovedFrom-52
Moving this nonessential bug to the next milestone.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 4 by ClusterFuzz, Jun 24 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4728984880807936

Fuzzer: bj_broddelwerk
Job Type: linux_asan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000010
Crash State:
  blink::DocumentMarkerController::markersInRange
  blink::SpellCheckRequest::create
  blink::SpellChecker::chunkAndMarkAllMisspellingsAndBadGrammar
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=144946:145047

Minimized Testcase (8.89 Kb): https://cluster-fuzz.appspot.com/download/AMIfv975T_LcaMlPA4Puag84mi8j_ZpomDKBVylBGbdU4Nqth6wNHGS4C0THjyD_tMrUNNaMzx-SyWeuKeykz2y1v8P_SsWvLT7Y3WN1UXEK0tVJbu4MdqYN3VCjyHFEPV9yHW8dKfwlunAS9Qit3x2CDTdgn9Skmw?testcase_id=4728984880807936

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Comment 5 by yosin@chromium.org, Jun 27 2016

Status: WontFix (was: Available)
Mark WontFix according to #c4
Project Member

Comment 6 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment