New issue
Advanced search Search tips

Issue 640719 link

Starred by 3 users

Issue metadata

Status: Fixed
Owner:
Closed: Aug 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows
Pri: 1
Type: Bug-Regression



Sign in to add a comment

Crash in blink::FrameHost::chromeClient

Project Member Reported by ClusterFuzz, Aug 24 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4613426867601408

Fuzzer: ochang_domfuzzer
Job Type: linux_asan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  blink::FrameHost::chromeClient
  blink::ScreenOrientationController::pageVisibilityChanged
  blink::PageVisibilityNotifier::notifyPageVisibilityChanged
  

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv941H2OpgmtadkYXrd12BU1e_1MHyDfD99HQT1qgv-b8M3rvhQ3YyngrYfZ1g-066SIWUmMrqMZWhKuRKC7PSitidQebH3qq2KwRAYzFpqUcuq7J2LImV0PYLiwVq29GpQuyK0BnqTMQzccjhw36a4TYydRgZw?testcase_id=4613426867601408


Additional requirements: Requires Gestures

Issue manually filed by: mmohammad

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: dcheng@chromium.org
Owner: haraken@chromium.org
Status: Assigned (was: Untriaged)
haraken@ could you please look into this.please feel free to re-assigned back if needed. thanks in advance 
Project Member

Comment 2 by bugdroid1@chromium.org, Aug 25 2016

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/1014f29772853eec10675e2febb6e0e8561cf440

commit 1014f29772853eec10675e2febb6e0e8561cf440
Author: haraken <haraken@chromium.org>
Date: Thu Aug 25 03:58:55 2016

frame()->host() may be null in ScreenOrientationController::pageVisibilityChanged

This CL adds a check to isActiveAndVisible() so that
ScreenOrientationController::pageVisibilityChanged don't access frame()->host()
which is already null.

BUG= 640719 

Review-Url: https://codereview.chromium.org/2272043003
Cr-Commit-Position: refs/heads/master@{#414301}

[modify] https://crrev.com/1014f29772853eec10675e2febb6e0e8561cf440/third_party/WebKit/Source/modules/screen_orientation/ScreenOrientationController.cpp

Comment 3 by dcheng@chromium.org, Aug 25 2016

Cc: pucchakayala@google.com
Issue 640720 has been merged into this issue.
Project Member

Comment 4 by sheriffbot@chromium.org, Aug 25 2016

Labels: Fracas


If this update was incorrect, please add "Fracas-Wrong" label to prevent future updates.

- Go/Fracas
Labels: -Type-Bug ReleaseBlock-Stable M-54 OS-Windows Type-Bug-Regression
This is a M54 regression issue started in # 54.0.2838.0

Not seen on any M53 builds.

Crash Link (with version impact distribution):
https://crash.corp.google.com/browse?q=product.name%3D%27Chrome%27%20AND%20custom_data.ChromeCrashProto.magic_signature_1.name%3D%27blink%3A%3AScreenOrientationController%3A%3ApageVisibilityChanged%27

Applying the RB label as this is a recent regression introduced in M54.
Project Member

Comment 6 by sheriffbot@chromium.org, Aug 25 2016

Labels: FoundIn-M-54
Users experienced this crash on the following builds:

Win Canary 54.0.2838.0 -  3.83 CPM, 93 reports, 89 clients (signature blink::ScreenOrientationController::pageVisibilityChanged)

If this update was incorrect, please add "Fracas-Wrong" label to prevent future updates.

- Go/Fracas
Project Member

Comment 7 by sheriffbot@chromium.org, Aug 25 2016

Labels: ReleaseBlock-Dev
This crash has high impact on Chrome's stability.
Signature: blink::ScreenOrientationController::pageVisibilityChanged.
Channel: canary. Platform: win.
Labeling  issue 640719  with ReleaseBlock-Dev.


If this update was incorrect, please add "Fracas-Wrong" label to prevent future updates.

- Go/Fracas
Labels: -ReleaseBlock-Dev -ReleaseBlock-Stable ReleaseBlock-Beta
Changing the dev blocker to beta blocker since the crash rate has come down on latest canary builds when compared to build # 54.0.2838.0

54.0.2839.2	5.63%	9	
54.0.2839.0	11.88%	19	
54.0.2838.2	9.38%	15	
54.0.2838.0	60.63%	97	
Status: Fixed (was: Assigned)

Comment 10 by ajha@chromium.org, Aug 26 2016

Labels: TE-Verified-54.0.2840.0 TE-Verified-M54
Duped Issue 640720 has not shown any crashes on the latest canary(54.0.2840.0 - 9 hours old) 

Link to the list of the builds:
=================================
https://crash.corp.google.com/browse?q=product.name%3D%27Chrome%27%20AND%20custom_data.ChromeCrashProto.magic_signature_1.name%3D%27blink%3A%3AScreenOrientationController%3A%3ApageVisibilityChanged%27

Marking this as Verified therefore.

Thank you!
Project Member

Comment 11 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment