Crash in blink::WebViewImpl::dragTargetDragOver |
||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5287125771878400 Fuzzer: inferno_layout_test_unmodified Job Type: windows_syzyasan_content_shell Platform Id: windows Crash Type: UNKNOWN Crash Address: 0x0000002b Crash State: blink::WebViewImpl::dragTargetDragOver test_runner::EventSender::DoDragAfterMouseUp test_runner::EventSender::PointerUp Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=399164:399271 Minimized Testcase (1.59 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95Q92hsC5aKAaVZyOWoy3rAWYJmIB7KWSCm_pv-vJlxTKznDRxTQgvbH0SjtLUgwuxOFpG8uNiXhft1kFGrPBMM6aAtRSZh1Sd6WdhGuwu_o0CGNRogSSyHu2WD1vzkz2u1IQ3zp_RSHaHJFw1UkJbZvA1M7A Filer: brajkumar See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jun 13 2016
Just confirmed that the bug was there even before crrev.com/2043053002.
,
Jun 13 2016
EventSender seems to expect a call to either EventSender::DoDragDrop or EventSender::BeginDragWithFiles before EventSender::PointerUp. crrev.com/1855513002 changed the drag-after-pointer-up a bit. Any chance this is causing the failure?
,
Jun 13 2016
I'm not sure. I need to investigate more about it.
,
Jun 13 2016
A few points I missed in my last post: - Reproduces in Linux: content_shell --run-layout-test ~/Downloads/fuzz-lyt-006111465741678.81.html - I couldn't locally revert crrev.com/1855513002 because of conflicts. Still the bast way IMO.
,
Jun 16 2016
ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5287125771878400 Fuzzer: inferno_layout_test_unmodified Job Type: windows_syzyasan_content_shell Platform Id: windows Crash Type: UNKNOWN Crash Address: 0x0000002b Crash State: blink::WebViewImpl::dragTargetDragOver test_runner::EventSender::DoDragAfterMouseUp test_runner::EventSender::PointerUp Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=399164:399271 Minimized Testcase (1.59 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95Q92hsC5aKAaVZyOWoy3rAWYJmIB7KWSCm_pv-vJlxTKznDRxTQgvbH0SjtLUgwuxOFpG8uNiXhft1kFGrPBMM6aAtRSZh1Sd6WdhGuwu_o0CGNRogSSyHu2WD1vzkz2u1IQ3zp_RSHaHJFw1UkJbZvA1M7A See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Aug 31 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jan 6 2017
,
Jan 7
This is not a very big deal anymore as we are gradually moving away from eventsender. |
||||||
►
Sign in to add a comment |
||||||
Comment 1 by brajkumar@chromium.org
, Jun 13 2016Labels: -Pri-1 findit-for-crash Te-Logged Pri-2
Owner: mustaq@chromium.org
Status: Assigned (was: Available)