New issue
Advanced search Search tips

Issue 625137 link

Starred by 1 user

Issue metadata

Status: Verified
Owner: ----
Closed: Jul 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug



Sign in to add a comment

Crash in content::GpuBenchmarking::GetGpuDriverBugWorkarounds

Project Member Reported by ClusterFuzz, Jul 1 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5872251929100288

Fuzzer: inferno_twister
Job Type: windows_syzyasan_content_shell
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 0x00000003
Crash State:
  content::GpuBenchmarking::GetGpuDriverBugWorkarounds
  base::internal::Invoker<base::internal::BindState<base::internal::RunnableAdapte
  gin::internal::Dispatcher<void __cdecl
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=402831:402879

Minimized Testcase (3.71 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95f_YV_XdKLTJ-uDLfVOM9azXqNALQeSsrX0rMuAVZeUGkqcKQugHBi4XUxOpT6PIKfwiu7jLDsP99fONCop6P_xgx0trpQxt0swjos3EonMBMs5UNX53GXBHOOr_0IIhx3mT4c60WnRnBiELuXEZhxr2f4QA?testcase_id=5872251929100288

Filer: tkonchada

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Components: Internals
Labels: findit-for-crash Te-Logged M-53
Owner: tzik@chromium.org
Status: Assigned (was: Available)
No CL in the regression range changes the crashed files. The result is the blame information.

Author: j.isorce
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/ff4a814529b414738c2f10ed0e57f021bc3d78a6
Time: Wed Apr 06 08:56:40 2016
The CL last changed line 958 of file gpu_benchmarking_extension.cc, which is stack frame 0.

Author: tzik
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/4435e804b6344b27942c68fd3c5b195daebacddb
Time: Wed May 11 23:05:05 2016
The CL last changed line 171 of file bind_internal.h, which is stack frame 1.

Author: tzik
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/ee2487294417a82adfc854aa680c7765eef7494e
Time: Wed Jun 01 08:22:51 2016
The CL last changed line 296 of file bind_internal.h, which is stack frame 2.

Author: tzik
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/ee2487294417a82adfc854aa680c7765eef7494e
Time: Wed Jun 01 08:22:51 2016
The CL last changed line 363 of file bind_internal.h, which is stack frame 3.

Author: tzik
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/caf1d84bb83aaf5369eb508027a685e2bf9859b4
Time: Tue Jun 28 12:22:21 2016
The CL last changed line 346 of file bind_internal.h, which is stack frame 4.

Author: tzik
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/77d41139d261342a429d2775c59d8e8a386d4c81
Time: Wed Mar 09 09:47:03 2016
The CL last changed line 389 of file callback.h, which is stack frame 5.

Author: kolczyk
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/735c49b6ad67166ccbcc8e3717681bb560fbf1cf
Time: Fri Oct 24 13:06:04 2014
The CL last changed line 183 of file function_template.h, which is stack frame 6.


Possible suspect : https://chromium.googlesource.com/chromium/src//+/caf1d84bb83aaf5369eb508027a685e2bf9859b4

Please reassign if this is not related to your change.
Project Member

Comment 2 by ClusterFuzz, Jul 1 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5872251929100288

Fuzzer: inferno_twister
Job Type: windows_syzyasan_content_shell
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 0x00000003
Crash State:
  content::GpuBenchmarking::GetGpuDriverBugWorkarounds
  base::internal::Invoker<base::internal::BindState<base::internal::RunnableAdapte
  gin::internal::Dispatcher<void __cdecl
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=402831:402879

Minimized Testcase (3.71 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95f_YV_XdKLTJ-uDLfVOM9azXqNALQeSsrX0rMuAVZeUGkqcKQugHBi4XUxOpT6PIKfwiu7jLDsP99fONCop6P_xgx0trpQxt0swjos3EonMBMs5UNX53GXBHOOr_0IIhx3mT4c60WnRnBiELuXEZhxr2f4QA?testcase_id=5872251929100288

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 3 by sheriffbot@chromium.org, Jul 2 2016

Labels: -M-53 M-54 MovedFrom-53
Moving this nonessential bug to the next milestone.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 4 by tzik@chromium.org, Jul 4 2016

Cc: tzik@chromium.org
Labels: findit-wrong
Owner: ----
Status: Available (was: Assigned)
Project Member

Comment 5 by ClusterFuzz, Jul 11 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4709893705826304

Fuzzer: inferno_twister_custom_bundle
Job Type: linux_asan_content_shell_drt
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  content::GpuBenchmarking::GetGpuDriverBugWorkarounds
  gin::internal::Dispatcher<void
  v8::internal::FunctionCallbackArguments::Call
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_content_shell_drt&range=404454:404473

Minimized Testcase (2.73 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94SSmTD64CkAjF7Tz12ED8ITAN62akMIFJS8YfjOIhhQpz4sxxEOdJKvUK4dBAQYCtZv-NSb2p8rnQKoPYMFdFXpYBIA6MVPbgsu_l9ZoaMz8bZJw8gk4SzjyJclKn3x9lHsmwr26bd9zWlajx7S8mbxuBeIw?testcase_id=4709893705826304

Filer: kavvaru

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Project Member

Comment 6 by ClusterFuzz, Jul 13 2016

ClusterFuzz has detected this issue as fixed in range 404631:404810.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4709893705826304

Fuzzer: inferno_twister_custom_bundle
Job Type: linux_asan_content_shell_drt
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  content::GpuBenchmarking::GetGpuDriverBugWorkarounds
  gin::internal::Dispatcher<void
  v8::internal::FunctionCallbackArguments::Call
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_content_shell_drt&range=404454:404473
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_content_shell_drt&range=404631:404810

Minimized Testcase (2.73 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94SSmTD64CkAjF7Tz12ED8ITAN62akMIFJS8YfjOIhhQpz4sxxEOdJKvUK4dBAQYCtZv-NSb2p8rnQKoPYMFdFXpYBIA6MVPbgsu_l9ZoaMz8bZJw8gk4SzjyJclKn3x9lHsmwr26bd9zWlajx7S8mbxuBeIw?testcase_id=4709893705826304

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 7 by ClusterFuzz, Jul 13 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Available)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 8 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment