Crash in chrome::GetBrowserContextRedirectedInIncognito |
||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5040898182479872 Fuzzer: meacer_chromebot_extensions Job Type: linux_asan_chrome_chromeos Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: chrome::GetBrowserContextRedirectedInIncognito KeyedServiceFactory::GetServiceForContext TemplateURLServiceFactory::GetForProfile Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_chromeos&range=316761:316782 Minimized Testcase (11.21 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95n79g_zBEcKQVVfx8B9zXPmqJccjALuh8AF4cr8Rv8euWtCxCCE64l5HzbPDu_bq5mIoDJnysJ9C4R4YZaZrU99z2YW-JXXKAgiSwfesOL67ruqvVDf0XX_WmwdnaXDFNvqqYQvap1_AUL6g1G0CYgTxrKXA Additional requirements: Requires Gestures Filer: durga.behera See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jun 15 2016
,
Jun 15 2016
missed the link for Comment #1. https://cs.chromium.org/chromium/src/chrome/browser/profiles/OWNERS
,
Jun 15 2016
Moving this nonessential bug to the next milestone. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jun 17 2016
,
Jun 20 2016
From the stack trace, it looks like this is crashing because profile_ is null when the following line is reached: https://cs.chromium.org/chromium/src/chrome/browser/ui/app_list/app_list_view_delegate.cc?sq=package:chromium&type=cs&l=827 Assigning to one of the owners of that file from chrome/browser/ui/app_list/OWNERS
,
Jun 23 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/ca75961e35cc647ae8375768b67d61276e14465a commit ca75961e35cc647ae8375768b67d61276e14465a Author: calamity <calamity@chromium.org> Date: Thu Jun 23 04:49:13 2016 Fix crash in app list view delegate. This CL fixes an issue where an observer was not removed from the app list view delegate when the profile was set to nullptr. This caused a crash if the TemplateURLService notified the app list view delegate. BUG= 620220 Review-Url: https://codereview.chromium.org/2082933002 Cr-Commit-Position: refs/heads/master@{#401541} [modify] https://crrev.com/ca75961e35cc647ae8375768b67d61276e14465a/chrome/browser/ui/app_list/app_list_view_delegate.cc
,
Jun 23 2016
,
Jun 24 2016
ClusterFuzz has detected this issue as fixed in range 401535:401544. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5040898182479872 Fuzzer: meacer_chromebot_extensions Job Type: linux_asan_chrome_chromeos Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: chrome::GetBrowserContextRedirectedInIncognito KeyedServiceFactory::GetServiceForContext TemplateURLServiceFactory::GetForProfile Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_chromeos&range=316761:316782 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_chromeos&range=401535:401544 Minimized Testcase (11.21 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95n79g_zBEcKQVVfx8B9zXPmqJccjALuh8AF4cr8Rv8euWtCxCCE64l5HzbPDu_bq5mIoDJnysJ9C4R4YZaZrU99z2YW-JXXKAgiSwfesOL67ruqvVDf0XX_WmwdnaXDFNvqqYQvap1_AUL6g1G0CYgTxrKXA?testcase_id=5040898182479872 Additional requirements: Requires Gestures See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Oct 18 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||||||
►
Sign in to add a comment |
||||||||
Comment 1 by durga.behera@chromium.org
, Jun 15 2016Components: Blink
Owner: anthonyvd@chromium.org
Status: Assigned (was: Available)