New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 690590 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 690493
Owner:
please use my google.com address
Closed: Feb 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in ForwardMessage

Project Member Reported by ClusterFuzz, Feb 9 2017

Issue description

Components: Internals>Mojo
Labels: Test-Predator-Correct-CLs M-58
Owner: roc...@chromium.org
Status: Assigned (was: Untriaged)
The result is a list of CLs that change the crashed files. 

Author: rockot
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/a628d0b45d5ce49a035020d8d67e9cc9a562ecac
Time: Thu Feb 09 08:40:15 2017
Lines 288 of file ipc_channel_mojo.cc which potentially caused crash are changed in this cl (frame #1, "IPC::ChannelMojo::ForwardMessageFromThreadSafePtr").
Minimum distance from crash line to modified line: 0. (file: ipc_channel_mojo.cc, crashed on: 288, modified: 288).
Mergedinto: 690493
Status: Duplicate (was: Assigned)
Project Member

Comment 3 by ClusterFuzz, Feb 11 2017

ClusterFuzz has detected this issue as fixed in range 449378:449562.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5082133438922752

Fuzzer: mbarbella_js_mutation_layout
Job Type: linux_lsan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  ForwardMessage
  IPC::ChannelMojo::ForwardMessageFromThreadSafePtr
  Invoke<const
  
Sanitizer: address (ASAN)

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=449206:449250
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=449378:449562

Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97Vt_dgTwMLEGyk59br_w8w1bS4jpLSqqnZmhkY_Bwxp3VNAWGceumIDMLjkBrcMx6fx4cK-sI-vA6w5ElVKWgyJqLJCJrYY7AQFVU1MeAlUw6oRLWsteMf61AZ5YYv2Yrn6lXfV6UXBITYsfApBLnLGwRE1zgAaoLNnFY8kTPK2wLOWr8gl4WhTKNHV1-hStFq3SWkZvtnS_-krnGkc5LUSw7Ll9XzkzFKw8b3rDrdwaiMHGQRciRJGDfy6a1ffHOo6bWZ8UGpCdLjigveArs2HY7IlrOBYwO_p11j_HTDzcnvtmSyHS_AYv69yFtEm_rOiq0uTD6bF-m_zqAGax8yAxD8fwpCsRBAufHo7VT0qCErsmm2UyqpWvv5SLge0VLs58SeZj4_-_Kzl_Vy3H-JNo1DJA?testcase_id=5082133438922752


Additional requirements: Requires Gestures

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Sign in to add a comment