New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 638151 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Last visit > 30 days ago
Closed: Aug 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Direct-leak in base::SparseHistogram::FactoryGet

Project Member Reported by ClusterFuzz, Aug 16 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6177240952078336

Fuzzer: language_detection_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: Direct-leak
Crash Address: 
Crash State:
  base::SparseHistogram::FactoryGet
  DetermineTextLanguage
  translate::DeterminePageLanguage
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=411575:411719

Minimized Testcase (0.02 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97zGF1SC_oK4nXcmtVP_J4fyNlGazJ4nibwFm3gMKHLEm9O9HAIv3UDeERTL1Py7u8gxbcKp7jKTpZI5oxvJ3vz7QAGUXJXL1b3jMHl5HX3G8GeZPoDGvTIhMLsLfvBFV03elJusCic70-kVFRWEMMNPKFMwQ?testcase_id=6177240952078336

Issue manually filed by: ajha

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 

Comment 1 by ajha@chromium.org, Aug 16 2016

Cc: ajha@chromium.org
Labels: Findit-for-crash M-54 Te-Logged
Owner: abakalov@chromium.org
Status: Assigned (was: Untriaged)
Findit-result:
==============
Suspected CLs	No CL in the regression range changes the crashed files. The result is the blame information.

Author: bcwhite
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/3dd85c4f5f230f7c1fa1055cb035c72196a46237
Time: Thu Mar 17 13:21:56 2016
The CL last changed line 48 of file sparse_histogram.cc, which is stack frame 1.

Author: abakalov
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/ba402369f1550c80c9df3155245af5db23a98b4d
Time: Tue Aug 09 16:56:55 2016
The CL last changed line 189 of file language_detection_util.cc, which is stack frame 2.

Author: mcindy
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/55614df31bd8645d20bd824a486305e9545eba09
Time: Thu Aug 06 23:46:49 2015
The CL last changed line 254 of file language_detection_util.cc, which is stack frame 3.

Author: krasin
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/f45d529d19dad67376809c81119f4f38c98f97ae
Time: Thu Oct 22 01:46:22 2015
The CL last changed line 34 of file language_detection_fuzzer.cc, which is stack frame 4.

Author: kcc
Project: chromium-libfuzzer
Changelist: https://chromium.googlesource.com/chromium/llvm-project/llvm/lib/Fuzzer.git/+/d33f707d488e6ac62cb5110f90115d9fe863c99e
Time: Sat Feb 13 17:56:51 2016
The CL last changed line 512 of file FuzzerLoop.cpp, which is stack frame 5.

Author: kcc
Project: chromium-libfuzzer
Changelist: https://chromium.googlesource.com/chromium/llvm-project/llvm/lib/Fuzzer.git/+/d33f707d488e6ac62cb5110f90115d9fe863c99e
Time: Sat Feb 13 17:56:51 2016
The CL last changed line 468 of file FuzzerLoop.cpp, which is stack frame 6.

Author: kcc
Project: chromium-libfuzzer
Changelist: https://chromium.googlesource.com/chromium/llvm-project/llvm/lib/Fuzzer.git/+/d05583bdc4ae06542f00e0837ceba145a0b6a7e7
Time: Wed May 04 20:44:50 2016
The CL last changed line 257 of file FuzzerDriver.cpp, which is stack frame 7.

Suspected Project: chromium

From the chromium regression changelog of the report.

Suspected change: https://codereview.chromium.org/2244683002

abakalov@: Could you please take a look at this and help in investigating this further.

Thank you!
Project Member

Comment 2 by ClusterFuzz, Aug 17 2016

ClusterFuzz has detected this issue as fixed in range 412260:412422.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6177240952078336

Fuzzer: language_detection_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: Direct-leak
Crash Address: 
Crash State:
  base::SparseHistogram::FactoryGet
  DetermineTextLanguage
  translate::DeterminePageLanguage
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=411575:411719
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=412260:412422

Minimized Testcase (0.02 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97zGF1SC_oK4nXcmtVP_J4fyNlGazJ4nibwFm3gMKHLEm9O9HAIv3UDeERTL1Py7u8gxbcKp7jKTpZI5oxvJ3vz7QAGUXJXL1b3jMHl5HX3G8GeZPoDGvTIhMLsLfvBFV03elJusCic70-kVFRWEMMNPKFMwQ?testcase_id=6177240952078336

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 3 by ClusterFuzz, Aug 17 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 4 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment