Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5249153677656064 Fuzzer: lcamtuf_cross_fuzz Job Type: linux_lsan_chrome_mp Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: MakeWeak v8::internal::GlobalHandles::MakeWeak SetWeak Sanitizer: address (ASAN) Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=441524:442831 Minimized Testcase (5.88 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96uDAFy4azhP9NWsKnM6AKteOxs9gZSzU3dbXVWSQhsnM-5XCP5qGvunCeu-maJlu5_0uvI2RCcq8Ge34_sa2_pSbMOo1u5Edr8phjuG88cSOcMmNonaSrTFf_8VX3AWw7qJBkUMt-Nx4D7SyIHKRyLZuTQEAf0QR-B8B6MnMA_Ra2kTw4bvwiOndBR3OXB7hjQI8cYCilNaJcm-iriobAPihBHgJnzoBlFfMTkCG0rNit2kaWpEaadGNtrANi7tmj33_kRSw4gTgovEzXjHrplNWQuH8VzawdcOx5Iz2Ve4NbsL-aHxoIuGx25mH3aCdsaGclnU4pS0q3Y96_U0ptSkdMreBkXv63J5kf9VDKu6D6aQVI?testcase_id=5249153677656064 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
rossberg@, please triage
Crash happens in Blink. @eisinger, can you please triage?
it looks like we might fail to create a wrapper for the Request* but don't check for it. I suspect the failure is here: https://cs.chromium.org/chromium/src/third_party/WebKit/Source/bindings/core/v8/V8PerContextData.cpp?rcl=1484626872&l=97 but the caller doesn't check the return value: https://cs.chromium.org/chromium/src/third_party/WebKit/Source/bindings/core/v8/ScriptWrappable.cpp?rcl=1484626872&l=29 (just a DCHECK)
ClusterFuzz has detected this issue as fixed in range 445279:445285. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5249153677656064 Fuzzer: lcamtuf_cross_fuzz Job Type: linux_lsan_chrome_mp Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: MakeWeak v8::internal::GlobalHandles::MakeWeak SetWeak Sanitizer: address (ASAN) Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=441524:442831 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=445279:445285 Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv95yVDvi3uZUfrzJB_VRG9D6OgYp2T4qa19-rX5Z-R9l64zVgjNOTrTKEVNpr1y-4IT0MVHWC5D3SLV5GS_X9QyctQ1RQUKBaxUTZiSj3-bNjq3UavqZLWt74ZsiriIprHtRva17WEzKveaxozxuYN89pyvlBRzQTb3pkrUKJHIUv5P_OSTZ_Y-TGEGrBIKVh3tzpTLpHjeBvY8zKJ-WyaeOiF-e5q92yRtT2Fih3BTpU4r1zUxDaqx4k4XW94rVG8BvPP9hdiy247xd_3oq5qf7u9KgJpugTKStADgq51kO-sl0llAIJjS0MGqpcsfYBqk8SPubtG39EG6Dw_DSdJT3A_YqMPZqkqqZaoaZ6xFUn7EEZ5o?testcase_id=5249153677656064 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
ClusterFuzz testcase 5249153677656064 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Comment 1 by mummare...@chromium.org
, Jan 14 2017