New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 627814 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Jul 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Chrome , Mac
Pri: 1
Type: Bug-Regression



Sign in to add a comment

Crash in pdf::PepperPDFHost::OnHostMsgHasUnsupportedFeature

Project Member Reported by ClusterFuzz, Jul 13 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6333440769392640

Fuzzer: ifratric_acrojs
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  pdf::PepperPDFHost::OnHostMsgHasUnsupportedFeature
  pdf::PepperPDFHost::OnResourceMessageReceived
  ppapi::host::ResourceMessageHandler::RunMessageHandlerAndReply
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=358557:358562

Minimized Testcase (2486.66 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95JQjjoHlAjJeS_DgHTBwWydGnxuQNzH6ihF5Pw_u7VxyoPAX1iR-BKVgTSXXZyC8za98-dx0y4_6rq72DiC8pS7F5yb7HZqMs50XpyMo0gCdz73e4RkT1W9c0SCjrviuolOQO0pxFF2aftBEwWvesReDMXdXlpth8xIyAHB5baZRBHUio?testcase_id=6333440769392640

Filer: rnimmagadda

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: raymes@chromium.org
Components: Internals>Plugins>PDF Tools>Test>FindIt>CorrectResult
Labels: -Type-Bug M-54 findit-for-crash Te-Logged Type-Bug-Regression
Owner: jam@chromium.org
Status: Assigned (was: Available)
Suspecting:

Author: jam@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/dade5f876b1649129f74442613ba7087efe181f6
Time: Tue May 13 21:59:21 2014
The CL last changed line 73 of file pepper_pdf_host.cc, which is stack frame 1.

Author: raymes@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/6dac73151fef7f1d4e48981075a690cc295ea61e
Time: Tue Nov 20 04:31:37 2012
The CL last changed line 30 of file resource_message_handler.cc, which is stack frame 2.

@jam/raymes: Could you please look into this issue.

Thank you.
Owner: thestig@chromium.org
Project Member

Comment 3 by bugdroid1@chromium.org, Jul 13 2016

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/a0cec3faf14da6bd8f78b8bfaa6147af8926a3e8

commit a0cec3faf14da6bd8f78b8bfaa6147af8926a3e8
Author: thestig <thestig@chromium.org>
Date: Wed Jul 13 23:06:29 2016

Add some CHECKs to PepperPDFHost to figure out a crash.

BUG= 627814 

Review-Url: https://codereview.chromium.org/2148063002
Cr-Commit-Position: refs/heads/master@{#405338}

[modify] https://crrev.com/a0cec3faf14da6bd8f78b8bfaa6147af8926a3e8/components/pdf/renderer/pepper_pdf_host.cc

Project Member

Comment 4 by ClusterFuzz, Jul 15 2016

ClusterFuzz has detected this issue as fixed in range 405185:405467.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6333440769392640

Fuzzer: ifratric_acrojs
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  pdf::PepperPDFHost::OnHostMsgHasUnsupportedFeature
  pdf::PepperPDFHost::OnResourceMessageReceived
  ppapi::host::ResourceMessageHandler::RunMessageHandlerAndReply
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=358557:358562
Fixed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=405185:405467

Minimized Testcase (2486.66 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95JQjjoHlAjJeS_DgHTBwWydGnxuQNzH6ihF5Pw_u7VxyoPAX1iR-BKVgTSXXZyC8za98-dx0y4_6rq72DiC8pS7F5yb7HZqMs50XpyMo0gCdz73e4RkT1W9c0SCjrviuolOQO0pxFF2aftBEwWvesReDMXdXlpth8xIyAHB5baZRBHUio?testcase_id=6333440769392640

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by ClusterFuzz, Jul 15 2016

ClusterFuzz has detected this issue as fixed in range 405185:405467.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6333440769392640

Fuzzer: ifratric_acrojs
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  pdf::PepperPDFHost::OnHostMsgHasUnsupportedFeature
  pdf::PepperPDFHost::OnResourceMessageReceived
  ppapi::host::ResourceMessageHandler::RunMessageHandlerAndReply
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=358557:358562
Fixed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=405185:405467

Minimized Testcase (2486.66 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95JQjjoHlAjJeS_DgHTBwWydGnxuQNzH6ihF5Pw_u7VxyoPAX1iR-BKVgTSXXZyC8za98-dx0y4_6rq72DiC8pS7F5yb7HZqMs50XpyMo0gCdz73e4RkT1W9c0SCjrviuolOQO0pxFF2aftBEwWvesReDMXdXlpth8xIyAHB5baZRBHUio?testcase_id=6333440769392640

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 6 by ClusterFuzz, Jul 15 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Cc: infe...@chromium.org
Labels: -ClusterFuzz-Verified ClusterFuzz-Wrong
Status: Assigned (was: Verified)
inferno: Can you help me out here? I only added some CHECKs and now CF thinks it's fixed?

Comment 8 by aarya@google.com, Jul 15 2016

You can reupload testcase using https://cluster-fuzz.appspot.com/#uploadusertestcase and reassociate with this bug by clicking "Update bug". This is working as expected, the crash is gone and check failure stack looks different, so CF considers this as fixed.
I looked around on the CF website but didn't find another crash report for this. Should there have been one? I'll muck around with this and also see if I ran repro locally with a Mac.
Labels: OS-Chrome OS-Linux OS-Windows
Maybe I can just wait a bit longer and see where users hit the CHECK.
Cc: mummare...@chromium.org thestig@chromium.org
 Issue 630474  has been merged into this issue.
Project Member

Comment 14 by bugdroid1@chromium.org, Jul 23 2016

Status: Fixed (was: Assigned)
Project Member

Comment 16 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: -ClusterFuzz-Wrong
We have made a bunch of changes on ClusterFuzz side, so resetting ClusterFuzz-Wrong label.

Sign in to add a comment