New issue
Advanced search Search tips

Issue 628860 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Aug 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in constrained_window::ShowWebModalDialogViews

Project Member Reported by ClusterFuzz, Jul 16 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6112369055105024

Fuzzer: ipc_fuzzer_gen
Job Type: linux_asan_chrome_ipc_32bit
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00000000
Crash State:
  constrained_window::ShowWebModalDialogViews
  ShowConstrainedWebDialog
  printing::PrintPreviewDialogController::CreatePrintPreviewDialog
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_ipc_32bit&range=356053:356243

Minimized Testcase (0.86 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94YMmvRqXeqUfQB7wW3zPrNt4zf0TpJCDj38xKOZl6eE_cISAnQnf-dAF20bqBs75oE7gvjiCugR9jc2jkPzCPH-ovqXmjQfHoIIQjd59zXwHsKP7N8voA6OX6AlRq5N6nhwA1TWzyigkeYdeSMgQhn5_psCw?testcase_id=6112369055105024

Filer: thestig

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: wjmaclean@chromium.org lazyboy@chromium.org hcarmona@chromium.org
Components: UI>Browser>PrintPreview
See also bug 489889 and bug 615433.
Labels: findit-for-crash M-52
Owner: msw@chromium.org
Status: Assigned (was: Available)
Suspected CLs	No CL in the regression range changes the crashed files. The result is the blame information.

Author: hcarmona
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/1d6674152570bc29ed98ea965c74c873de595587
Time: Mon Jul 06 19:56:48 2015
The CL last changed line 156 of file constrained_window_views.cc, which is stack frame 0.

Author: msw@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/20960d488457c4aafd3f707a097258791d678ec4
Time: Fri Jun 06 02:54:56 2014
The CL last changed line 143 of file constrained_window_views.cc, which is stack frame 1.

Author: oshima
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/dd3db6a1bb9b162e4f55e9c16b2890a4b60bef03
Time: Mon Nov 10 22:21:23 2014
The CL last changed line 276 of file constrained_web_dialog_delegate_views.cc, which is stack frame 2.

Author: apacible
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/bdcf05d84a94245a8e6dd0e7bcd08796a78a5a86
Time: Sun Dec 14 21:39:41 2014
The CL last changed line 360 of file print_preview_dialog_controller.cc, which is stack frame 3.

Author: wittman@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/e6c97f6de21efd3e693a1afda435cc3b9a9eb2c7
Time: Fri Aug 02 00:47:05 2013
The CL last changed line 183 of file print_preview_dialog_controller.cc, which is stack frame 4.

Author: hcarmona
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/8720794e92dc9c82466a608d2cec1dc8fc8adabb
Time: Thu Jan 14 05:43:47 2016
The CL last changed line 168 of file print_preview_dialog_controller.cc, which is stack frame 5.

Author: thestig@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/d8ce31e1d2473c404aa59b1f29687d46d4f628cc
Time: Wed Dec 19 05:09:21 2012
The CL last changed line 98 of file print_preview_message_handler.cc, which is stack frame 6.

Suspected Project: chromium

Possible suspect : https://chromium.googlesource.com/chromium/src//+/20960d488457c4aafd3f707a097258791d678ec4

Please reassign if this is not related to your change

Comment 4 by msw@chromium.org, Jul 18 2016

Cc: msw@chromium.org
Owner: hcarmona@chromium.org
Hector, can you take a look? Is this a dup of Issue 489889?
Project Member

Comment 5 by ClusterFuzz, Aug 10 2016

ClusterFuzz has detected this issue as fixed in range 410634:410757.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6112369055105024

Fuzzer: ipc_fuzzer_gen
Job Type: linux_asan_chrome_ipc_32bit
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00000000
Crash State:
  constrained_window::ShowWebModalDialogViews
  ShowConstrainedWebDialog
  printing::PrintPreviewDialogController::CreatePrintPreviewDialog
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_ipc_32bit&range=356053:356243
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_ipc_32bit&range=410634:410757

Minimized Testcase (0.86 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94YMmvRqXeqUfQB7wW3zPrNt4zf0TpJCDj38xKOZl6eE_cISAnQnf-dAF20bqBs75oE7gvjiCugR9jc2jkPzCPH-ovqXmjQfHoIIQjd59zXwHsKP7N8voA6OX6AlRq5N6nhwA1TWzyigkeYdeSMgQhn5_psCw?testcase_id=6112369055105024

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 6 by ClusterFuzz, Aug 10 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 7 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment