New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 658580 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 572802
Owner:
Last visit > 30 days ago
Closed: Oct 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in printing::GetPlugin

Project Member Reported by ClusterFuzz, Oct 23 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4796103544537088

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_lsan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  printing::GetPlugin
  PrintingNodeOrPdfFrame
  IsModifiable
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=351585:351815

Minimized Testcase (0.55 Kb): https://cluster-fuzz.appspot.com/download/AMIfv971y8PEhVK42kuDIZZ9eaLuHV89B6Jso0--41OpIVE2SVFOcWxyaVhGLv1lqylZDy-3blojtTig6Qe1BAEDHxZRoFl5_Qs0u6PZv9nbxM7GvBtCLoimS4vWRg_W88lFEblGLYJaeft1SOcsi-CmnynL4nvr4Q?testcase_id=4796103544537088

Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Components: Internals>Printing
Labels: Test-Predator-Correct
Owner: tzik@chromium.org
Status: Assigned (was: Untriaged)
Suspected CLs:
==============
Git blame below is NOT necessarily who introduced the crash nor the owner for it. Please check the code before assigning to anyone.(No CL in the regression range changed the crashing files.)

Author: dgn
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/4686a2a414777e0d7b28175bf4594666e953fda5
Time: Thu Feb 05 23:40:27 2015
The CL last changed line 292 of file print_web_view_helper.cc, which is stack frame 0.

Author: abarth@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/a1221aea536d832d7e3d30c991f8ad1cd8b44193
Time: Thu Nov 07 01:31:30 2013
The CL last changed line 301 of file print_web_view_helper.cc, which is stack frame 1.

Author: vitalybuka@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/0f4f439c20dd63fe4fba45da83179aa67b4b8d93
Time: Thu May 23 19:18:02 2013
The CL last changed line 2130 of file print_web_view_helper.cc, which is stack frame 2.

Author: dgn
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/4686a2a414777e0d7b28175bf4594666e953fda5
Time: Thu Feb 05 23:40:27 2015
The CL last changed line 1849 of file print_web_view_helper.cc, which is stack frame 3.

Author: tzik
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/27d1e313968955f1a120b65b31e316263365b1b3
Time: Tue Sep 13 05:28:59 2016
The CL last changed line 47 of file callback.h, which is stack frame 4.

Author: tzik
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/739ffe3fd7b83bcb9ef7eb2e4b5c52fdbf35f59d
Time: Fri Oct 14 14:34:58 2016
The CL last changed line 52 of file task_annotator.cc, which is stack frame 5.

Author: tzik
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/739ffe3fd7b83bcb9ef7eb2e4b5c52fdbf35f59d
Time: Fri Oct 14 14:34:58 2016
The CL last changed line 358 of file task_queue_manager.cc, which is stack frame 6.

Suspected Project: chromium
Suspected Component: Internals>Printing

From the above Cl list suspecting the below:
https://chromium.googlesource.com/chromium/src/+/739ffe3fd7b83bcb9ef7eb2e4b5c52fdbf35f59d
tzik@ : Could you please take a look into this if its related to your change.

Comment 2 by tzik@chromium.org, Oct 25 2016

Owner: durga.behera@chromium.org
It's not related to the PendingTask change.
Mergedinto: 572802
Status: Duplicate (was: Assigned)
Project Member

Comment 4 by ClusterFuzz, Nov 16 2016

ClusterFuzz has detected this issue as fixed in range 432285:432416.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4796103544537088

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_lsan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  printing::GetPlugin
  PrintingNodeOrPdfFrame
  IsModifiable
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=351585:351815
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=432285:432416

Minimized Testcase (0.55 Kb): https://cluster-fuzz.appspot.com/download/AMIfv971y8PEhVK42kuDIZZ9eaLuHV89B6Jso0--41OpIVE2SVFOcWxyaVhGLv1lqylZDy-3blojtTig6Qe1BAEDHxZRoFl5_Qs0u6PZv9nbxM7GvBtCLoimS4vWRg_W88lFEblGLYJaeft1SOcsi-CmnynL4nvr4Q?testcase_id=4796103544537088

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment