Issue metadata
Sign in to add a comment
|
Crash in blink::ThreadState::getPersistentRegion |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6417573642240000 Fuzzer: attekett_dom_fuzzer Job Type: linux_asan_chrome_media Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000010 Crash State: blink::ThreadState::getPersistentRegion blink::PersistentBase<blink::Geolocation, base::internal::Invoker<base::internal::BindState<void Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=403412:403423 Minimized Testcase (6.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97L3fGlg3yllUeWMaJ_aZhfYV3ghGw4foNDNGacJWfmA98jKzfbQ8iyB7loZzRcWvu7IDbWwdkYapfgEySpqGr_yfp6jai9LlTiWruUBd7SNiPL22CqW9SVTNuoXsLRspSVkS2ZYlCPf4wNm1ug5W2CaGiZ0g?testcase_id=6417573642240000 Additional requirements: Requires Gestures Filer: rnimmagadda See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jul 14 2016
It is not too interesting to look for suspects at the top of the stack for these kinds of bugs.. Re-assigning to tzik@ -- a (too) late shutdown of a geolocation callback object. A latent problem perhaps, but its intro is related to https://codereview.chromium.org/2091713002
,
Jul 14 2016
,
Jul 14 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/33871d83b7ee98a1aa5692f8f835d44b7da65ef5 commit 33871d83b7ee98a1aa5692f8f835d44b7da65ef5 Author: tzik <tzik@chromium.org> Date: Thu Jul 14 12:12:06 2016 Pass weak pointer by ref in Bind implementation Weak pointer in Bind impl is historically passed by value, however when a blink::WeakPersistent is passed as a receiver of a method after blink::ThreadState is destroyed, it can no longer be copied and causes crash. BUG= 627820 Review-Url: https://codereview.chromium.org/2145383002 Cr-Commit-Position: refs/heads/master@{#405475} [modify] https://crrev.com/33871d83b7ee98a1aa5692f8f835d44b7da65ef5/base/bind_internal.h
,
Jul 14 2016
ClusterFuzz has detected this issue as fixed in range 405467:405481. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6417573642240000 Fuzzer: attekett_dom_fuzzer Job Type: linux_asan_chrome_media Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000010 Crash State: blink::ThreadState::getPersistentRegion blink::PersistentBase<blink::Geolocation, base::internal::Invoker<base::internal::BindState<void Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=403412:403423 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=405467:405481 Minimized Testcase (6.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97L3fGlg3yllUeWMaJ_aZhfYV3ghGw4foNDNGacJWfmA98jKzfbQ8iyB7loZzRcWvu7IDbWwdkYapfgEySpqGr_yfp6jai9LlTiWruUBd7SNiPL22CqW9SVTNuoXsLRspSVkS2ZYlCPf4wNm1ug5W2CaGiZ0g?testcase_id=6417573642240000 Additional requirements: Requires Gestures See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jul 14 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Sep 22 2017
,
Sep 22 2017
|
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by rnimmagadda@chromium.org
, Jul 13 2016Components: Blink>Location
Labels: -Type-Bug M-54 findit-for-crash Te-Logged Type-Bug-Regression
Owner: sigbjo...@opera.com
Status: Assigned (was: Available)