New issue
Advanced search Search tips

Issue 659876 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Oct 2016
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in base::debug::DebugBreak

Project Member Reported by ClusterFuzz, Oct 27 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4755328668532736

Fuzzer: libfuzzer_net_http_security_headers_hpkp_report_only_fuzzer
Job Type: libfuzzer_chrome_asan_debug
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x03e900006890
Crash State:
  base::debug::DebugBreak
  url::UIDNAWrapper::UIDNAWrapper
  base::DefaultLazyInstanceTraits<url::UIDNAWrapper>::New
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=427711:427755

Minimized Testcase (0.77 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94HaZRPp91Oi_OSEuPFUH8fWrPpz1HyXPN2Iql6Ety2o2pqTi_m1z_xCf9VyrDh9hDIlXeLMWu3G7L58nIbPCo5AzBxDO8lPVjgMs05KPt8IdOVBX3Te-nvoXtgSWhgyUEv3HkTVBf4ZWBfAioax3x0joesEg?testcase_id=4755328668532736

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Owner: ellyjo...@chromium.org
Status: Assigned (was: Untriaged)
Suspected CLs	
=========================
Git blame below is NOT necessarily who introduced the crash nor the owner for it. Please check the code before assigning to anyone.(No CL in the regression range changed the crashing files.)

Author: mostynb@opera.com
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/901a5e3835718e8872f38af32d65fce7ea3fcbeb
Time: Mon Apr 08 23:26:25 2013
The CL last changed line 221 of file debugger_posix.cc, which is stack frame 2.

Author: brettw@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/58580359a452cb7c3b9580edc0843c3ab3d158df
Time: Tue Oct 26 04:07:50 2010
The CL last changed line 251 of file debugger_posix.cc, which is stack frame 3.

Author: rch@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/82d89abc03ea6fd6b9258f0e57be0290b33d7eb1
Time: Fri Feb 28 18:25:34 2014
The CL last changed line 748 of file logging.cc, which is stack frame 4.

Author: ellyjones
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/c9547bec4f1bd1072083163a4a106ab5ffea62c1
Time: Wed Jun 24 18:38:00 2015
The CL last changed line 104 of file url_canon_icu.cc, which is stack frame 5.

Author: craig.schlenter@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/c1aeaac2015e93e1168453d4de29619c43fda669
Time: Fri Mar 12 15:28:48 2010
The CL last changed line 69 of file lazy_instance.h, which is stack frame 6.
=========================
Suspected Project: chromium

From code search on the file "url_canon_icu.cc" suspecting the below.
https://codereview.chromium.org/1210523003
ellyjones@ : Could you please take alook into this if its related to your change.
Project Member

Comment 2 by ClusterFuzz, Oct 28 2016

ClusterFuzz has detected this issue as fixed in range 428149:428255.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4755328668532736

Fuzzer: libfuzzer_net_http_security_headers_hpkp_report_only_fuzzer
Job Type: libfuzzer_chrome_asan_debug
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x03e900006890
Crash State:
  base::debug::DebugBreak
  url::UIDNAWrapper::UIDNAWrapper
  base::DefaultLazyInstanceTraits<url::UIDNAWrapper>::New
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=427711:427755
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=428149:428255

Minimized Testcase (0.77 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94HaZRPp91Oi_OSEuPFUH8fWrPpz1HyXPN2Iql6Ety2o2pqTi_m1z_xCf9VyrDh9hDIlXeLMWu3G7L58nIbPCo5AzBxDO8lPVjgMs05KPt8IdOVBX3Te-nvoXtgSWhgyUEv3HkTVBf4ZWBfAioax3x0joesEg?testcase_id=4755328668532736

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 3 by ClusterFuzz, Oct 28 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 4 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment