New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 665188 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Nov 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 1
Type: Bug



Sign in to add a comment

CreateWaitAndExitThread(base::TimeDelta::FromSeconds(60)) in child_thread_impl.c

Project Member Reported by ClusterFuzz, Nov 14 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5476524225724416

Fuzzer: attekett_dom_fuzzer
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: CHECK failure
Crash Address: 
Crash State:
  CreateWaitAndExitThread(base::TimeDelta::FromSeconds(60)) in child_thread_impl.c
  content::SuicideOnChannelErrorFilter::OnChannelError
  IPC::ChannelProxy::Context::OnChannelError
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=416606:416613

Minimized Testcase (8.84 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94n7VXYlIhB1XDFnEyHDLo_FCZXLi3dIvcOA-OYWhvIYzMGwPzml_ZesJVYCEuBn2EMUnoWla7HQF7aZfwg6ZlMy50YceXV8vEM7IDHeTYXngSCeQLdUncrKaM426qJC6z-4QpKfLxLhmQPGAj72ZNjemYF8A?testcase_id=5476524225724416

Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 

Comment 1 by tapted@chromium.org, Nov 16 2016

Owner: tzik@chromium.org
Status: Assigned (was: Untriaged)
[mac triage] The bisect is small. Suspecting

Make blink::TimerBase own the WebTaskRunner for timer task

BUG=624696

Review-Url: https://codereview.chromium.org/2290243002
Cr-Commit-Position: refs/heads/master@{#416612}



Seems to be

INVALID_OPERATION : glTexSubImage2D: level 0 does not exist
[32478:21855:1115/002140:ERROR:platform_thread_posix.cc(119)] pthread_create: Resource temporarily unavailable
[32478:21855:1115/002140:FATAL:child_thread_impl.cc(160)] Check failed: CreateWaitAndExitThread(base::TimeDelta::FromSeconds(60)).
0   Chromium Framework                  0x000000025cd14190 _ZN4base5debug10StackTraceC1Ev + 32
1   Chromium Framework                  0x000000025cd8330f _ZN7logging10LogMessageD2Ev + 415
2   Chromium Framework                  0x00000002680d4310 _ZN7content12_GLOBAL__N_127SuicideOnChannelErrorFilter14OnChannelErrorEv + 448
3   Chromium Framework                  0x000000025fd9f232 _ZN3IPC12ChannelProxy7Context14OnChannelErrorEv + 434
4   Chromium Framework                  0x000000025fda0be8 _ZN3IPC12ChannelProxy7Context13OnSendMessageENSt3__110unique_ptrINS_7MessageENS2_14default_deleteIS4_EEEE + 568
5   Chromium Framework                  0x000000025fda779a _ZN4base8internal7InvokerINS0_9BindStateIMN3IPC12ChannelProxy7ContextEFvNSt3__110unique_ptrINS3_7MessageENS6_14default_deleteIS8_EEEEEJ13scoped_refptrIS5_ENS0_13PassedWrapperISB_EEEEEFvvEE3RunEPNS0_13BindStateBaseE + 634


Maybe it's a clusterfuzz glitch though.

Comment 2 by tapted@chromium.org, Nov 16 2016

Cc: robhogan@chromium.org
The test case has some transform stuff, so perhaps also

Apply first-line transform-text style
BUG= 129669 

Review-Url: https://codereview.chromium.org/2305833002
Cr-Commit-Position: refs/heads/master@{#416608}

Project Member

Comment 3 by ClusterFuzz, Nov 22 2016

ClusterFuzz has detected this issue as fixed in range 433417:433418.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5476524225724416

Fuzzer: attekett_dom_fuzzer
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: CHECK failure
Crash Address: 
Crash State:
  CreateWaitAndExitThread(base::TimeDelta::FromSeconds(60)) in child_thread_impl.c
  content::SuicideOnChannelErrorFilter::OnChannelError
  IPC::ChannelProxy::Context::OnChannelError
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=416606:416613
Fixed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=433417:433418

Minimized Testcase (8.84 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94n7VXYlIhB1XDFnEyHDLo_FCZXLi3dIvcOA-OYWhvIYzMGwPzml_ZesJVYCEuBn2EMUnoWla7HQF7aZfwg6ZlMy50YceXV8vEM7IDHeTYXngSCeQLdUncrKaM426qJC6z-4QpKfLxLhmQPGAj72ZNjemYF8A?testcase_id=5476524225724416

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 4 by ClusterFuzz, Nov 22 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 5 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment