New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 629307 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Aug 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug



Sign in to add a comment

message_buffer_.size() + chunk.data.size() <= message_buffer_size_ in devtools_a

Project Member Reported by ClusterFuzz, Jul 18 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5044426460364800

Fuzzer: ipc_fuzzer_gen
Job Type: windows_asan_chrome_ipc
Platform Id: windows

Crash Type: CHECK failure
Crash Address: 
Crash State:
  message_buffer_.size() + chunk.data.size() <= message_buffer_size_ in devtools_a
  content::DevToolsMessageChunkProcessor::ProcessChunkedMessageFromAgent
  content::RenderFrameDevToolsAgentHost::OnDispatchOnInspectorFrontend
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_asan_chrome_ipc&range=405858:405980

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv948rspsx0z9Bo68HGjY9-ItAmlKSqKdyJ0uu72nmS6pxp5Hwww9R2kObwdH_PX5V_49qWsrJG6UClQzdHLpnMp12FFTyp5y6sVO9n8ArNO-q6ECMgAp8vfrmWmDm5TF68oNsHUPA43TiW94Au81am5_Rp7U5NPdLp_33-HDJoKa-3v3oZo?testcase_id=5044426460364800


Additional requirements: Requires Gestures

Filer: mummareddy

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Labels: M-54 findit-wrong Te-Logged
Owner: roc...@chromium.org
Status: Assigned (was: Available)
As code search on file render_process_host_impl.cc, recent changes done by rockot@. could you please take a look and help us to find exact owner.

Comment 2 by roc...@chromium.org, Jul 18 2016

Owner: pfeldman@chromium.org
I don't think this has anything to do with changes in render_process_host_impl.cc

Over to devtools for triage
Status: Fixed (was: Assigned)
Project Member

Comment 5 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment