New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 619478 link

Starred by 1 user

Issue metadata

Status: Assigned
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 3
Type: Bug



Sign in to add a comment

Crash in blink::WebViewImpl::dragTargetDragOver

Project Member Reported by ClusterFuzz, Jun 13 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5287125771878400

Fuzzer: inferno_layout_test_unmodified
Job Type: windows_syzyasan_content_shell
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 0x0000002b
Crash State:
  blink::WebViewImpl::dragTargetDragOver
  test_runner::EventSender::DoDragAfterMouseUp
  test_runner::EventSender::PointerUp
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=399164:399271

Minimized Testcase (1.59 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95Q92hsC5aKAaVZyOWoy3rAWYJmIB7KWSCm_pv-vJlxTKznDRxTQgvbH0SjtLUgwuxOFpG8uNiXhft1kFGrPBMM6aAtRSZh1Sd6WdhGuwu_o0CGNRogSSyHu2WD1vzkz2u1IQ3zp_RSHaHJFw1UkJbZvA1M7A

Filer: brajkumar

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: durga.behera@chromium.org
Labels: -Pri-1 findit-for-crash Te-Logged Pri-2
Owner: mustaq@chromium.org
Status: Assigned (was: Available)
No CL in the regression range changes the crashed files. The result is the blame information.

Author: mustaq
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/abca6ff6e9ffb9791242701d4499e0144ed94283
Time: Thu Jun 09 17:29:53 2016
The CL last changed line 1085 of file event_sender.cc, which is stack frame 5.

Suspected Project: chromium
===============================
Above mentioned is the CL's list from findit, Suspecting the file of "event_sender.cc" from the frame #5 .

mustaq@: Could you please look into this issue if it is related to your change, else please help us in assigning it to the right owner.

Thanks!

Comment 2 by mustaq@chromium.org, Jun 13 2016

Just confirmed that the bug was there even before crrev.com/2043053002.

Comment 3 by mustaq@chromium.org, Jun 13 2016

Cc: mustaq@chromium.org
Owner: nzolghadr@chromium.org
EventSender seems to expect a call to either EventSender::DoDragDrop or EventSender::BeginDragWithFiles before EventSender::PointerUp.

crrev.com/1855513002 changed the drag-after-pointer-up a bit. Any chance this is causing the failure?

I'm not sure. I need to investigate more about it.

Comment 5 by mustaq@chromium.org, Jun 13 2016

A few points I missed in my last post:

- Reproduces in Linux:
  content_shell --run-layout-test ~/Downloads/fuzz-lyt-006111465741678.81.html

- I couldn't locally revert crrev.com/1855513002 because of conflicts. Still the bast way IMO.

Project Member

Comment 6 by ClusterFuzz, Jun 16 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5287125771878400

Fuzzer: inferno_layout_test_unmodified
Job Type: windows_syzyasan_content_shell
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 0x0000002b
Crash State:
  blink::WebViewImpl::dragTargetDragOver
  test_runner::EventSender::DoDragAfterMouseUp
  test_runner::EventSender::PointerUp
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=399164:399271

Minimized Testcase (1.59 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95Q92hsC5aKAaVZyOWoy3rAWYJmIB7KWSCm_pv-vJlxTKznDRxTQgvbH0SjtLUgwuxOFpG8uNiXhft1kFGrPBMM6aAtRSZh1Sd6WdhGuwu_o0CGNRogSSyHu2WD1vzkz2u1IQ3zp_RSHaHJFw1UkJbZvA1M7A

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Components: Blink>Input
Project Member

Comment 8 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: Hotlist-Input-Dev
Labels: -Pri-2 Pri-3
This is not a very big deal anymore as we are gradually moving away from eventsender.

Sign in to add a comment