New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 614114 link

Starred by 0 users

Issue metadata

Status: Fixed
Owner: ----
Closed: May 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug



Sign in to add a comment

Crash in blink::WebURLResponse::url

Project Member Reported by ClusterFuzz, May 23 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4830767162589184

Fuzzer: ochang_domfuzzer
Job Type: windows_asan_content_shell
Platform Id: windows

Crash Type: UNKNOWN READ
Crash Address: 0x00000004
Crash State:
  blink::WebURLResponse::url
  content::MojoContextState::OnFetchModuleComplete
  base::internal::Invoker<base::IndexSequence<0,1>,base::internal::BindState<base:
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_asan_content_shell&range=379564:379959

Minimized Testcase (24.44 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97gxTIerABz31qkLXcNhDWSgvXuoLDrKfWmIdHcD_dlMQIHV4HMMM6yfSZHVH74EgjPSV3WPxl3pXNmNMHPZfXRfDoo1DlC13bX80A2rBPAhlGNRG0rfrjcroeIWNlrgwROOCI38u7AAyECmXCJBkW1D52K_OiY1zszSdSp_wGRpLVaTrY

Filer: reillyg

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: yzshen@chromium.org
This crash looks like the standard response to attempting to load a Mojo module that doesn't exist. We should really make mojo.define() resilient to that to prevent false positives when constructing fuzz test cases against layout tests.

Comment 2 by yzshen@chromium.org, May 23 2016

Cc: roc...@chromium.org

Comment 3 by yzshen@chromium.org, May 23 2016

What revision of Chromium did you see this crash with?

Has this CL already fixed the problem?
https://chromium.googlesource.com/chromium/src/+/2eb97bdbc5ebc7fec94c53010b064c677e4cab8f
Status: Fixed (was: Available)
From the report it looks like the crash happened at r379959 so yes, that patch has likely fixed the issue.
Project Member

Comment 5 by ClusterFuzz, Jun 9 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4830767162589184

Fuzzer: ochang_domfuzzer
Job Type: windows_asan_content_shell
Platform Id: windows

Crash Type: UNKNOWN READ
Crash Address: 0x00000004
Crash State:
  blink::WebURLResponse::url
  content::MojoContextState::OnFetchModuleComplete
  base::internal::Invoker<base::IndexSequence<0,1>,base::internal::BindState<base:
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_asan_content_shell&range=379564:379959

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv964GKBamSoD8rWMM0hTxIVr-U_I4VLUszubW5b4GIqQnd5BbJnnkpqfDwkhFVQVUyldujlHaXz902Zb1w0emSfD8JUxPv_V97A54XREvaBl3i8q3srH5RyGbnPNhvTMZzIKQE5sZQxsSQPdYX3TI755AsIjDXGlBOiiLGth-TG4e8v6n-0


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 6 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment