New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 618300 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Out until 24 Jan
Closed: Jun 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 1
Type: Bug



Sign in to add a comment

Crash in extensions::WebAccessibleResourcesInfo::IsResourceWebAccessible

Project Member Reported by ClusterFuzz, Jun 8 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5780502674145280

Fuzzer: attekett_surku_fuzzer
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: UNKNOWN READ
Crash Address: 0x000000000058
Crash State:
  extensions::WebAccessibleResourcesInfo::IsResourceWebAccessible
  extensions::ExtensionNavigationThrottle::WillStartRequest
  content::NavigationHandleImpl::WillStartRequest
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=398017:398351

Minimized Testcase (0.11 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv97c4Ri4lgEdCYGz8mRsXP91ocjp_HJFY31DNKgyjxp8kotEBkId10RILX9uWELvIJ2HDrH2-A4EuXM-FURoQ2va3v-LWM7ipg68WZYYcy9oCzHjCn_ma6bJgveHXuPuzGQ2YseI3ilBvNdLo2VNbZnMhxRiLw
<iframe src="chrome-extension://iadeocfgjdjdmpenejdbfeaocpbikmab/activation_in_offline.html"
                 >


Filer: ashejole

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: ashej...@chromium.org
Components: Internals>Core Tools>Test>FindIt>CorrectResult
Labels: findit-for-crash Te-Logged M-53
Owner: nasko@chromium.org
Status: Assigned (was: Available)
Suspected CLs	The result is a list of CLs that change the crashed files.

Author: nasko
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/b9164c43d2900c967f4fdb5ebfc4812f7e914116
Time: Tue Jun 07 01:21:35 2016
Lines 445 of file navigation_handle_impl.cc which potentially caused crash are changed in this cl (frame #3, "CheckWillStartRequest").

Files extension_navigation_throttle.cc, navigation_resource_throttle.cc are changed in this cl (and is part of stack frame #2, "extensions::ExtensionNavigationThrottle::WillStartRequest")
Minimum distance from crash line to modified line: 0. (file: navigation_handle_impl.cc, crashed on: 445, modified: 445).

Suspected Project: chromium
Suspected Component: Internals>Core

@naskko: Hey, would you mind checking the above issue as per suspected CL ?

I really appreciate your help.

Thank you!

Comment 2 by nasko@chromium.org, Jun 8 2016

D'oh! Yes, it is my CL and the bug is obvious. I'll put up a CL sometime today.
Project Member

Comment 3 by bugdroid1@chromium.org, Jun 8 2016

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/7e87b4385d57cecc692ceb8b581ecf95215950fd

commit 7e87b4385d57cecc692ceb8b581ecf95215950fd
Author: nasko <nasko@chromium.org>
Date: Wed Jun 08 18:40:41 2016

Check for registry and extension existence before web_accessible_resources.

BUG= 618300 

Review-Url: https://codereview.chromium.org/2048693004
Cr-Commit-Position: refs/heads/master@{#398627}

[modify] https://crrev.com/7e87b4385d57cecc692ceb8b581ecf95215950fd/extensions/browser/extension_navigation_throttle.cc

Comment 4 by nasko@chromium.org, Jun 8 2016

Status: Fixed (was: Assigned)

Comment 5 by nasko@chromium.org, Jun 8 2016

Cc: manoranjanr@google.com nasko@chromium.org
Issue 618410 has been merged into this issue.
Project Member

Comment 6 by ClusterFuzz, Jun 9 2016

ClusterFuzz has detected this issue as fixed in range 398606:398628.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5780502674145280

Fuzzer: attekett_surku_fuzzer
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: UNKNOWN READ
Crash Address: 0x000000000058
Crash State:
  extensions::WebAccessibleResourcesInfo::IsResourceWebAccessible
  extensions::ExtensionNavigationThrottle::WillStartRequest
  content::NavigationHandleImpl::WillStartRequest
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=398017:398351
Fixed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=398606:398628

Minimized Testcase (0.15 Kb): https://cluster-fuzz.appspot.com/download/AMIfv946aVpDTvejuYOJTlJV5CoOUEM5I0fME-FXdx3EVxONhfNuRan49g5zqUjITB7JIJuHFt7_fRFqDJzvu2QXm-JnEcXvjXTHmFlRe1zo0vWODIecCycNfHpNpCBr_IhlPjF49bcmPaavBz5W4k9DFmYlZtvrAw

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
@nasko: Thanks a lot for quick turnaround.

Thank you!
Project Member

Comment 8 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment