New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 621709 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Jun 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug



Sign in to add a comment

Crash in content::DeviceOrientationEventPump::SendFakeDataForTesting

Project Member Reported by ClusterFuzz, Jun 20 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5315174626230272

Fuzzer: inferno_layout_test_unmodified
Job Type: windows_syzyasan_content_shell
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 0x00000003
Crash State:
  content::DeviceOrientationEventPump::SendFakeDataForTesting
  base::internal::Invoker<base::IndexSequence<0,1>,base::internal::BindState<base:
  base::debug::TaskAnnotator::RunTask
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=400189:400221

Minimized Testcase (0.30 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv97tzPuGZJ-W3_g4p8ZI1pgJUk-ubUEWp-sZa9qShTQHjQNZ1wB3K7dlTnAgRojQ57nQ5scD2fi_pCoh0qY_zizBPaBro0XkRPNJVHQcbZDfPfkwvgy3XuROtHwOvYXcaL3X0d4txFnViukyzG9sSGKOvXHoFQ?testcase_id=5315174626230272
  <script>
function __f_37() {
      document.writeln();
;
}


    
</script>
<body onload="__f_218();">
  <script>
var mockGamma = 3.3;
    testRunner.setMockDeviceOrientation();
;
window.addEventListener('deviceorientation', function() {
});
function __f_218() {
 __f_37(); 

}
</script>


Filer: mummareddy

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: timvolod...@chromium.org mlamouri@chromium.org
Labels: findit-wrong Te-Logged M-53
Owner: tzik@chromium.org
Status: Assigned (was: Available)
From findit tool:

Author: tzik
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/ee2487294417a82adfc854aa680c7765eef7494e
Time: Wed Jun 01 08:22:51 2016
The CL last changed line 312 of file bind_internal.h, which is stack frame 2.
Project Member

Comment 2 by ClusterFuzz, Jun 21 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6438541240565760

Fuzzer: inferno_twister
Job Type: linux_asan_content_shell_drt
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  content::DeviceMotionEventPump::SendFakeDataForTesting
  base::debug::TaskAnnotator::RunTask
  scheduler::TaskQueueManager::ProcessTaskFromWorkQueue
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_content_shell_drt&range=397991:398001

Minimized Testcase (10.63 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96fBWf_z-64bvHPM5pBdz8rAIOX-5o03zjHdilZJ3cai_REbuVDHJ6vJT3q25YwSCR3yzXpa1YuJbJTfHcDHVVWOAAYVXD6JFWMMTFxXZz0Gz5bmTVluOHxeXhUfWvgUPwWKdLJpS4_wJenw5x_2FPMISdvCw?testcase_id=6438541240565760

Additional requirements: Requires HTTP

Filer: mummareddy

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Project Member

Comment 3 by ClusterFuzz, Jun 22 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6438541240565760

Fuzzer: inferno_twister
Job Type: linux_asan_content_shell_drt
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  content::DeviceMotionEventPump::SendFakeDataForTesting
  base::debug::TaskAnnotator::RunTask
  scheduler::TaskQueueManager::ProcessTaskFromWorkQueue
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_content_shell_drt&range=397991:398001

Minimized Testcase (10.63 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96fBWf_z-64bvHPM5pBdz8rAIOX-5o03zjHdilZJ3cai_REbuVDHJ6vJT3q25YwSCR3yzXpa1YuJbJTfHcDHVVWOAAYVXD6JFWMMTFxXZz0Gz5bmTVluOHxeXhUfWvgUPwWKdLJpS4_wJenw5x_2FPMISdvCw?testcase_id=6438541240565760

Additional requirements: Requires HTTP

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Status: WontFix (was: Assigned)
As per comment#3, marking the bug as wontfix. thanks.
Project Member

Comment 5 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment