Issue metadata
Sign in to add a comment
|
Direct-leak in std::__1::unique_ptr<WTF::Function<base::internal::MakeUnboundRunTypeImpl<void |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5843013452693504 Fuzzer: bj_broddelwerk Job Type: linux_lsan_chrome_mp Platform Id: linux Crash Type: Direct-leak Crash Address: Crash State: std::__1::unique_ptr<WTF::Function<base::internal::MakeUnboundRunTypeImpl<void void blink::HTMLDocumentParser::postTaskToLookaheadParser<void blink::HTMLDocumentParser::startBackgroundParser Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=401251:401526 Minimized Testcase (1.17 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94Bl1W2wuM4LjVvQocARqXAohbRLge8gV0UTMcNPP2ZdsY4sjS4G91JSGjvh4U1vdyvrftlNbobwGKRsCgHB-9agAYYjEzeE-HyG60gdO1duJmyQNl_msvXDjvCkZdXfgOnFQycqkgvkqr459U-xO5ikU53YA?testcase_id=5843013452693504 Filer: ssamanoori See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jul 15 2016
Moving this nonessential bug to the next milestone. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jul 16 2016
,
Jul 19 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6007068779872256 Fuzzer: inferno_layout_test_unmodified Job Type: linux_lsan_chrome_mp Platform Id: linux Crash Type: Direct-leak Crash Address: Crash State: std::__1::unique_ptr<WTF::Function<base::internal::MakeUnboundRunTypeImpl<void void blink::HTMLDocumentParser::postTaskToLookaheadParser<void blink::HTMLDocumentParser::startBackgroundParser Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=209699:209703 Minimized Testcase (1.43 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95yQ3qX-slJ0SyXIuRO0ULgCNprLdr_4-Bn9_rhIQAYTIy69zET7xyh8FfwkEK0_ue9Kgpp4M3o35DuX-Fbdpgg51t66ZUg7DqZcH5lILgLz5PCUR4oRmEiw6Q5BK3LNTkQgDzOWB_HGraJw4JTthu_mo3mYg?testcase_id=6007068779872256 Filer: mummareddy See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Aug 14 2016
ClusterFuzz has detected this issue as fixed in range 411875:411885. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6007068779872256 Fuzzer: inferno_layout_test_unmodified Job Type: linux_lsan_chrome_mp Platform Id: linux Crash Type: Direct-leak Crash Address: Crash State: std::__1::unique_ptr<WTF::Function<base::internal::MakeUnboundRunTypeImpl<void void blink::HTMLDocumentParser::postTaskToLookaheadParser<void blink::HTMLDocumentParser::startBackgroundParser Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=209699:209703 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=411875:411885 Minimized Testcase (1.43 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95yQ3qX-slJ0SyXIuRO0ULgCNprLdr_4-Bn9_rhIQAYTIy69zET7xyh8FfwkEK0_ue9Kgpp4M3o35DuX-Fbdpgg51t66ZUg7DqZcH5lILgLz5PCUR4oRmEiw6Q5BK3LNTkQgDzOWB_HGraJw4JTthu_mo3mYg?testcase_id=6007068779872256 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Aug 14 2016
ClusterFuzz has detected this issue as fixed in range 411875:411885. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5843013452693504 Fuzzer: bj_broddelwerk Job Type: linux_lsan_chrome_mp Platform Id: linux Crash Type: Direct-leak Crash Address: Crash State: std::__1::unique_ptr<WTF::Function<base::internal::MakeUnboundRunTypeImpl<void void blink::HTMLDocumentParser::postTaskToLookaheadParser<void blink::HTMLDocumentParser::startBackgroundParser Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=401251:401526 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=411875:411885 Minimized Testcase (1.17 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94Bl1W2wuM4LjVvQocARqXAohbRLge8gV0UTMcNPP2ZdsY4sjS4G91JSGjvh4U1vdyvrftlNbobwGKRsCgHB-9agAYYjEzeE-HyG60gdO1duJmyQNl_msvXDjvCkZdXfgOnFQycqkgvkqr459U-xO5ikU53YA?testcase_id=5843013452693504 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Aug 14 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Aug 14 2016
So, I think this is wrong. The fixed range shows has: https://codereview.chromium.org/2221193002 Which adds testing configs to put the BackgroundHTMLParser on the main thread on bots. I don't think this should be marked as fixed until that experiment lands on HEAD. The test case should still repro locally.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Nov 23 2017
This issue has been Available for over a year. If it's no longer important or seems unlikely to be fixed, please consider closing it out. If it is important, please re-triage the issue. Sorry for the inconvenience if the bug really should have been left as Available. If you change it back, also remove the "Hotlist-Recharge-Cold" label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Dec 27 2017
,
Dec 27
This issue has been Available for over a year. If it's no longer important or seems unlikely to be fixed, please consider closing it out. If it is important, please re-triage the issue. Sorry for the inconvenience if the bug really should have been left as Available. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jan 7
I think BackgroundHTMLParser-on-the-main-thread is default now. |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by ssamanoori@chromium.org
, Jul 15 2016Labels: -Type-Bug findit-for-crash Te-Logged M-53 Type-Bug-Regression
Owner: abarth@chromium.org
Status: Assigned (was: Available)