Issue metadata
Sign in to add a comment
|
Crash in content::GpuBenchmarking::GetGpuDriverBugWorkarounds |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5030562809249792 Fuzzer: inferno_twister Job Type: windows_syzyasan_content_shell Platform Id: windows Crash Type: UNKNOWN Crash Address: 0x00000003 Crash State: content::GpuBenchmarking::GetGpuDriverBugWorkarounds base::internal::Invoker<base::internal::BindState<void gin::internal::Dispatcher<void __cdecl Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=404473:404552 Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv94exufAygz9mJjzgPvQW9TqfXJbLnLrb7RXeYWvyOOtGlHsaJPrHfXKKgCTjy3r5YLPBoyzWaqfrDnT7nmgLiEjpW7YGFsgVPsIXquBjtvlzBY63DhwpJEcQuh0cxMGyWTWmJTIWv9TyQaMz10k2P5o2jtfTK5DEFg89a3d4McYATM4kVY?testcase_id=5030562809249792 Filer: ajha See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jul 13 2016
I made a quick fix for the only problem I could see: https://codereview.chromium.org/2143913002/ (I think It cannot be a threading problem, since GpuChannelHost::Send() can use a sync_filter_.) Is it possible with cluster-fuzz to try the minimal test case with that CL ? I do not have permissions to explore it.
,
Jul 13 2016
It seems unlikely to me that this stack trace is accurate. There is only one call to GpuBenchmarking::Install in the entire code base: https://cs.chromium.org/chromium/src/content/renderer/render_frame_impl.cc?sq=package:chromium&dr=C&rcl=1468423091&l=3495 Without that extension installed, it's not possible to call any of the methods on GpuBenchmarking. I don't see these flags being installed in the run of content_shell. Could someone please verify that this bug is real?
,
Jul 13 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/9c74d43d235e97058f6327ffa292098b64f07036 commit 9c74d43d235e97058f6327ffa292098b64f07036 Author: j.isorce <j.isorce@samsung.com> Date: Wed Jul 13 20:40:58 2016 Check for GpuChannelHost nullity in GetGpuDriverBugWorkarounds BUG= 627392 R=kbr@chromium.org Review-Url: https://codereview.chromium.org/2143913002 Cr-Commit-Position: refs/heads/master@{#405282} [modify] https://crrev.com/9c74d43d235e97058f6327ffa292098b64f07036/content/renderer/gpu/gpu_benchmarking_extension.cc
,
Jul 14 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6184833391001600 Fuzzer: inferno_twister Job Type: mac_asan_content_shell Platform Id: mac Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: content::GpuBenchmarking::GetGpuDriverBugWorkarounds gin::internal::Dispatcher<void v8::internal::FunctionCallbackArguments::Call Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_content_shell&range=404631:404813 Minimized Testcase (3.06 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94foxr9JmTiPGIk-YX7ph6t_DgmiwXl3cu8Wj-u9LmDzUeEJxT97adSye_J_j4ssOjhZfSwhes7zcKxLfqb7GcN0sx3I3eUK62rfFRelqelp8TyNUOk8BbltWxca2rAR7G_h0KiXFTAYR_JHuBkGwMOAlqxSg?testcase_id=6184833391001600 Filer: ranjitkan See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jul 15 2016
ClusterFuzz has detected this issue as fixed in range 405185:405467. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6184833391001600 Fuzzer: inferno_twister Job Type: mac_asan_content_shell Platform Id: mac Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: content::GpuBenchmarking::GetGpuDriverBugWorkarounds gin::internal::Dispatcher<void v8::internal::FunctionCallbackArguments::Call Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_content_shell&range=404631:404813 Fixed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_content_shell&range=405185:405467 Minimized Testcase (3.06 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94foxr9JmTiPGIk-YX7ph6t_DgmiwXl3cu8Wj-u9LmDzUeEJxT97adSye_J_j4ssOjhZfSwhes7zcKxLfqb7GcN0sx3I3eUK62rfFRelqelp8TyNUOk8BbltWxca2rAR7G_h0KiXFTAYR_JHuBkGwMOAlqxSg?testcase_id=6184833391001600 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Aug 16 2016
> ClusterFuzz has detected this issue as fixed in range 405185:405467. So I am marking this issue as Fixed.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by ajha@chromium.org
, Jul 12 2016Components: Internals>Core
Labels: -Type-Bug M-54 findit-for-crash Te-Logged Type-Bug-Regression
Owner: j.iso...@samsung.com
Status: Assigned (was: Available)