New issue
Advanced search Search tips

Issue 626982 link

Starred by 2 users

Issue metadata

Status: Verified
Owner: ----
Closed: Sep 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in blink::reportFatalErrorInMainThread

Project Member Reported by ClusterFuzz, Jul 11 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5135737800622080

Fuzzer: inferno_layout_test_fuzzer
Job Type: linux_asan_content_shell_drt
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00009f7537dd
Crash State:
  blink::reportFatalErrorInMainThread
  v8::V8::FromJustIsNothing
  WebCoreTestSupport::injectInternalsObject
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_content_shell_drt&range=390623:390629

Minimized Testcase (0.48 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96jEPJGv1cmlp1-sRaAM0Q12oSo-LITa0IzGSCCfDduAcWyjbFtsYsMP_bkOA51qNOKHLI2dQhglmsyGH1E3OB-lv5MxF2e4lhw8P8UCRHyk-rFHFKhPane-otXVLj3gG_tznqFL98ym0MlHyx5c4y5gbFhog?testcase_id=5135737800622080

Filer: nyerramilli

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: nyerramilli@chromium.org
Components: Tools>Test>FindIt>WrongResult Blink>JavaScript
Labels: findit-wrong Te-Logged M-52
providing findit results for internal purpose:
Suspected CLs	No CL in the regression range changes the crashed files. The result is the blame information.

Author: haraken@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/e481f62ffcfa36c8460cc8ee6e69da863ae66b56
Time: Wed Nov 21 11:25:18 2012
The CL last changed line 96 of file V8Initializer.cpp, which is stack frame 0.

Author: svenpanne@chromium.org
Project: chromium-v8
Changelist: https://chromium.googlesource.com/v8/v8.git/+/111e604e7278baab96ce0c30e9cbea6f39599dd2
Time: Tue Jan 14 09:37:45 2014
The CL last changed line 335 of file api.cc, which is stack frame 1.

Author: svenpanne@chromium.org
Project: chromium-v8
Changelist: https://chromium.googlesource.com/v8/v8.git/+/ad605de2b54fcfe310354293cf22a88b21673c7b
Time: Mon Jan 13 09:42:23 2014
The CL last changed line 184 of file api.h, which is stack frame 2.

Author: jochen
Project: chromium-v8
Changelist: https://chromium.googlesource.com/v8/v8.git/+/ac23150fd2be43fcda9ad12dc118c6b16d96cdb6
Time: Wed Apr 15 07:11:54 2015
The CL last changed line 805 of file api.cc, which is stack frame 3.

Author: jochen
Project: chromium-v8
Changelist: https://chromium.googlesource.com/v8/v8.git/+/ac23150fd2be43fcda9ad12dc118c6b16d96cdb6
Time: Wed Apr 15 07:11:54 2015
The CL last changed line 6896 of file v8.h, which is stack frame 4.

Author: bashi@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/479c58134e3d3f23946e66959be5cf9a36eb71e8
Time: Tue May 12 06:56:13 2015
The CL last changed line 97 of file V8BindingMacros.h, which is stack frame 5.

Author: esprehn@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/3d68871098103c4b120e0ea46d31a3a6d7ca37c9
Time: Mon Jun 22 20:46:52 2015
The CL last changed line 69 of file WebCoreTestSupport.cpp, which is stack frame 6.

Suspected Project: chromium-v8
Suspected Component: Blink>JavaScript

requesting v8 team to check the issue and update.
Project Member

Comment 2 by ClusterFuzz, Jul 13 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5019247399141376

Fuzzer: inferno_twister
Job Type: mac_asan_content_shell
Platform Id: mac

Crash Type: UNKNOWN WRITE
Crash Address: 0x0000fbadbeef
Crash State:
  blink::reportFatalErrorInMainThread
  v8::V8::FromJustIsNothing
  WebCoreTestSupport::injectInternalsObject
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_content_shell&range=329193:329640

Minimized Testcase (0.21 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv94k4-70tF0jD4zWXL6jFr0qOvbHfGiorS4cNESCrpCuH8h0TMDGEI-50vYhiQK4C9ayVKl3CTaPqIQhVtqid4Kt9FouFDsz82TikglK9UOmcS8d9Df_E2JmmWKwj9VSYEUmO_9dx18lH_hBvn5Yo-CNvtYyeQ?testcase_id=5019247399141376
<script>
  testRunner.setCanOpenWindows();
  var newWindow = window.open( 'width=100,height=150');
  newWindow.__defineSetter__('internals', function() { internals = v; modifyPropertyOrValue(); });
    </script>


Filer: rnimmagadda

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Project Member

Comment 3 by ClusterFuzz, Aug 18 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5616280843583488

Fuzzer: lcamtuf_cross_fuzz
Job Type: linux_asan_chrome_chromeos
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00009f7537dd
Crash State:
  blink::reportFatalErrorInMainThread
  v8::V8::ToLocalEmpty
  blink::V8DOMWrapper::createWrapper
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_chromeos&range=411073:411126

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97H6aifsBUBq71B90T7xBkB7Tbdvq6qJxo4qSMsdOH_ikrkivcj8vZV7zvZRQtoUumFItEOnJERbT8lRvcy7XIO5LXouxXfedID2qDaaVAyWoQuAh8WQnFcZncnyTO643ctokMNs9aDVJpvIqzg43wUnunbpg?testcase_id=5616280843583488


Issue manually filed by: mummareddy

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Project Member

Comment 4 by ClusterFuzz, Aug 23 2016

ClusterFuzz has detected this issue as fixed in range 413383:413409.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5616280843583488

Fuzzer: lcamtuf_cross_fuzz
Job Type: linux_asan_chrome_chromeos
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00009f7537dd
Crash State:
  blink::reportFatalErrorInMainThread
  v8::V8::ToLocalEmpty
  blink::V8DOMWrapper::createWrapper
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_chromeos&range=411073:411126
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_chromeos&range=413383:413409

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97H6aifsBUBq71B90T7xBkB7Tbdvq6qJxo4qSMsdOH_ikrkivcj8vZV7zvZRQtoUumFItEOnJERbT8lRvcy7XIO5LXouxXfedID2qDaaVAyWoQuAh8WQnFcZncnyTO643ctokMNs9aDVJpvIqzg43wUnunbpg?testcase_id=5616280843583488


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by ClusterFuzz, Sep 15 2016

ClusterFuzz has detected this issue as fixed in range 418162:418172.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5019247399141376

Fuzzer: inferno_twister
Job Type: mac_asan_content_shell
Platform Id: mac

Crash Type: UNKNOWN WRITE
Crash Address: 0x0000fbadbeef
Crash State:
  blink::reportFatalErrorInMainThread
  v8::V8::FromJustIsNothing
  WebCoreTestSupport::injectInternalsObject
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_content_shell&range=329193:329640
Fixed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_content_shell&range=418162:418172

Minimized Testcase (0.21 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv94k4-70tF0jD4zWXL6jFr0qOvbHfGiorS4cNESCrpCuH8h0TMDGEI-50vYhiQK4C9ayVKl3CTaPqIQhVtqid4Kt9FouFDsz82TikglK9UOmcS8d9Df_E2JmmWKwj9VSYEUmO_9dx18lH_hBvn5Yo-CNvtYyeQ?testcase_id=5019247399141376
<script>
  testRunner.setCanOpenWindows();
  var newWindow = window.open( 'width=100,height=150');
  newWindow.__defineSetter__('internals', function() { internals = v; modifyPropertyOrValue(); });
    </script>


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 6 by ClusterFuzz, Sep 23 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6635781060034560

Fuzzer: lcamtuf_cross_fuzz
Job Type: linux_asan_chrome_chromeos
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00009f7537dd
Crash State:
  blink::reportFatalErrorInMainThread
  v8::V8::ToLocalEmpty
  blink::V8DOMWrapper::createWrapper
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_chromeos&range=419731:419755

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv974D0-hxQMCFNL4lh7VJHs0sF3g8LVjsp17rh3ct5Q-dX5HWATAj5o57HmBbOxvPSvf_5US8gjL8BneY5Iy132GPAuB6tGFZBisvFryXnS4C35cfUwl_I6Qb-I8JKMx7GEaTqP_zha6oAQHlmjzAKp5gjUInO-3KIU07paFoCKpCBc0_B8?testcase_id=6635781060034560


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Project Member

Comment 7 by ClusterFuzz, Sep 23 2016

ClusterFuzz has detected this issue as fixed in range 420372:420465.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6635781060034560

Fuzzer: lcamtuf_cross_fuzz
Job Type: linux_asan_chrome_chromeos
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00009f7537dd
Crash State:
  blink::reportFatalErrorInMainThread
  v8::V8::ToLocalEmpty
  blink::V8DOMWrapper::createWrapper
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_chromeos&range=419731:419755
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_chromeos&range=420372:420465

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv974D0-hxQMCFNL4lh7VJHs0sF3g8LVjsp17rh3ct5Q-dX5HWATAj5o57HmBbOxvPSvf_5US8gjL8BneY5Iy132GPAuB6tGFZBisvFryXnS4C35cfUwl_I6Qb-I8JKMx7GEaTqP_zha6oAQHlmjzAKp5gjUInO-3KIU07paFoCKpCBc0_B8?testcase_id=6635781060034560


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 8 by ClusterFuzz, Sep 23 2016

ClusterFuzz has detected this issue as fixed in range 420372:420502.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5135737800622080

Fuzzer: inferno_layout_test_fuzzer
Job Type: linux_asan_content_shell_drt
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00009f7537dd
Crash State:
  blink::reportFatalErrorInMainThread
  v8::V8::FromJustIsNothing
  WebCoreTestSupport::injectInternalsObject
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_content_shell_drt&range=390623:390629
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_content_shell_drt&range=420372:420502

Minimized Testcase (0.48 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96jEPJGv1cmlp1-sRaAM0Q12oSo-LITa0IzGSCCfDduAcWyjbFtsYsMP_bkOA51qNOKHLI2dQhglmsyGH1E3OB-lv5MxF2e4lhw8P8UCRHyk-rFHFKhPane-otXVLj3gG_tznqFL98ym0MlHyx5c4y5gbFhog?testcase_id=5135737800622080

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 9 by ClusterFuzz, Sep 23 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Available)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Components: -Tools>Test>FindIt>WrongResult
Labels: Test-Predator-Wrong
Project Member

Comment 11 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment