New issue
Advanced search Search tips

Issue 616076 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Jun 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Regression



Sign in to add a comment

ASSERTION FAILED: !currentCount

Project Member Reported by ClusterFuzz, May 31 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6302481533632512

Fuzzer: inferno_webbot
Job Type: linux_debug_chrome
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  ASSERTION FAILED: !currentCount
  blink::ThreadState::runTerminationGC
  blink::ThreadHeap::detach
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_chrome&range=144946:145047

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv95clo_O6TZzTjRQDPtxsdxZccjElUybPA71MgNzVnvnfMrukrGWZEWdugqeEr4CQhwWr8DzxgytRJU6Lb5S40ZbMT93qjHdgG51M9fPkRso3gAo-jl40v9Epo7DNMHDnrvLpy_QUOzEW4A_siTMOYRV0-xHqA


Additional requirements: Requires Gestures

Filer: ajha

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 

Comment 1 by ajha@chromium.org, May 31 2016

Components: Blink>MemoryAllocator
Labels: -Type-Bug findit-for-crash Te-Logged M-51 Type-Bug-Regression
Owner: keishi@chromium.org
Status: Assigned (was: Available)
Suspected CLs	No CL in the regression range changes the crashed files. The result is the blame information.

Author: keishi
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/75da88a74e60c92b4456b06f254aa6919b4dee01
Time: Wed Apr 27 12:58:58 2016
The CL last changed line 251 of file ThreadState.cpp, which is stack frame 0.

Author: keishi
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/75da88a74e60c92b4456b06f254aa6919b4dee01
Time: Wed Apr 27 12:58:58 2016
The CL last changed line 272 of file Heap.cpp, which is stack frame 1.

Author: keishi
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/75da88a74e60c92b4456b06f254aa6919b4dee01
Time: Wed Apr 27 12:58:58 2016
The CL last changed line 312 of file ThreadState.cpp, which is stack frame 2.

Author: keishi
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/75da88a74e60c92b4456b06f254aa6919b4dee01
Time: Wed Apr 27 12:58:58 2016
The CL last changed line 68 of file WebThreadSupportingGC.cpp, which is stack frame 3.

Author: skyostil@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/2d82362a939ba426544618a2f3f315360b0302f5
Time: Thu May 14 11:36:03 2015
The CL last changed line 81 of file HTMLParserThread.cpp, which is stack frame 4.

Author: yutak
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/fbbd4c94d77ab61145beff792e4adbe6c3239582
Time: Fri Feb 26 07:07:32 2016
The CL last changed line 167 of file Functional.h, which is stack frame 5.

Author: finnur
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/54fbc836be8606f1a4f65e5b32411f5ffc68750c
Time: Thu Mar 03 10:41:04 2016
The CL last changed line 350 of file Functional.h, which is stack frame 6.

Suspected Project: chromium-blink
Suspected Component: Blink>MemoryAllocator

Based on the above Find it result assigning to keishi@ for more inputs and further investigation of this.

Project Member

Comment 2 by ClusterFuzz, Jun 24 2016

ClusterFuzz has detected this issue as fixed in range 401259:401272.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6302481533632512

Fuzzer: inferno_webbot
Job Type: linux_debug_chrome
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  ASSERTION FAILED: !currentCount
  blink::ThreadState::runTerminationGC
  blink::ThreadHeap::detach
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_chrome&range=144946:145047
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_chrome&range=401259:401272

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv95clo_O6TZzTjRQDPtxsdxZccjElUybPA71MgNzVnvnfMrukrGWZEWdugqeEr4CQhwWr8DzxgytRJU6Lb5S40ZbMT93qjHdgG51M9fPkRso3gAo-jl40v9Epo7DNMHDnrvLpy_QUOzEW4A_siTMOYRV0-xHqA?testcase_id=6302481533632512


Additional requirements: Requires Gestures

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Comment 3 by sigbjo...@opera.com, Jun 24 2016

Status: Fixed (was: Assigned)
Project Member

Comment 4 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment