New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 705837 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Mar 2017
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in content::LevelDBIteratorImpl::IsValid

Project Member Reported by ClusterFuzz, Mar 28 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=6583278808334336

Fuzzer: therealholden_worker
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x000000000000
Crash State:
  content::LevelDBIteratorImpl::IsValid
  content::LevelDBTransaction::TransactionIterator::HandleConflictsAndDeletes
  content::LevelDBTransaction::TransactionIterator::Next
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=459919:459938

Reproducer Testcase: https://clusterfuzz.com/download/AMIfv96vdT4XD6YJbBALdMfYAMIiIU-7RLkYO6oZSOKOp8Ku6MRIC_5Fp2lO8X7Z6iPLTxxiENsdcPl_djOqDJqCGEcYyaohE45nPOsmOXt1EGQBUF1-U1lsH3N97qvCD7qE7_8H7m3brN8SuW2IuBdnA0P9BKxNKZ0NrbKt_fiRCsZhAAQYiPuUWoEjfJpyKG0W8XfTqnYz0tgCbKc_Mu_kEZZL0tD0HvsrmywTVVhYxNtqHcWkIMxkyNnUy7cHwMTuS5rL_8l94VOYGDF0T_2L37FoLegnXw0KLt--ToolSmx9ci-eAQUthdgVMrFueQb8fH8yRUzfr3vGBSkgwv-UozQWFzEeSKS9LwoxaeLCnWGaE-moJPwIe_LwRN-lYhrU3kNSlHuFnnmqY405em-ZaY_Yyy5lNw?testcase_id=6583278808334336


Additional requirements: Requires HTTP

Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: msrchandra@chromium.org
Labels: Test-Predator-Wrong M-59
Owner: dmu...@chromium.org
Status: Assigned (was: Untriaged)
Predator and CL did not provide any possible suspects.
Using Code Search for the file, "LevelDBIteratorImpl" assigning to the concern owner.
Suspecting Commit#
https://chromium.googlesource.com/chromium/src/+/ec764054b12a8e21e1fe958c3f1e4d47df671066

@dmurph -- Could you please look into the issue, kindly re-assign if it is not related to your changes.
Thank You.

Comment 2 by dmu...@chromium.org, Mar 28 2017

Ah! I see the bug. Patch soon.
Project Member

Comment 3 by ClusterFuzz, Mar 30 2017

ClusterFuzz has detected this issue as fixed in range 460478:460541.

Detailed report: https://clusterfuzz.com/testcase?key=6583278808334336

Fuzzer: therealholden_worker
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x000000000000
Crash State:
  content::LevelDBIteratorImpl::IsValid
  content::LevelDBTransaction::TransactionIterator::HandleConflictsAndDeletes
  content::LevelDBTransaction::TransactionIterator::Next
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=459919:459938
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=460478:460541

Reproducer Testcase: https://clusterfuzz.com/download/AMIfv96vdT4XD6YJbBALdMfYAMIiIU-7RLkYO6oZSOKOp8Ku6MRIC_5Fp2lO8X7Z6iPLTxxiENsdcPl_djOqDJqCGEcYyaohE45nPOsmOXt1EGQBUF1-U1lsH3N97qvCD7qE7_8H7m3brN8SuW2IuBdnA0P9BKxNKZ0NrbKt_fiRCsZhAAQYiPuUWoEjfJpyKG0W8XfTqnYz0tgCbKc_Mu_kEZZL0tD0HvsrmywTVVhYxNtqHcWkIMxkyNnUy7cHwMTuS5rL_8l94VOYGDF0T_2L37FoLegnXw0KLt--ToolSmx9ci-eAQUthdgVMrFueQb8fH8yRUzfr3vGBSkgwv-UozQWFzEeSKS9LwoxaeLCnWGaE-moJPwIe_LwRN-lYhrU3kNSlHuFnnmqY405em-ZaY_Yyy5lNw?testcase_id=6583278808334336


Additional requirements: Requires HTTP

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 4 by ClusterFuzz, Mar 30 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 6583278808334336 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 5 by bugdroid1@chromium.org, Apr 3 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/a812312f165c373e9f9fb684b229bb5a987e9328

commit a812312f165c373e9f9fb684b229bb5a987e9328
Author: pwnall <pwnall@chromium.org>
Date: Mon Apr 03 19:04:49 2017

Test for IndexedDB crashing bug found by clusterfuzz.

BUG= 705837 

Review-Url: https://codereview.chromium.org/2779273004
Cr-Commit-Position: refs/heads/master@{#461495}

[add] https://crrev.com/a812312f165c373e9f9fb684b229bb5a987e9328/third_party/WebKit/LayoutTests/external/wpt/IndexedDB/parallel-cursors-upgrade.html

Project Member

Comment 7 by bugdroid1@chromium.org, Apr 5 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/8a1c41840a061c7de4dfe40a4f2f5713645d8800

commit 8a1c41840a061c7de4dfe40a4f2f5713645d8800
Author: maxmorin <maxmorin@chromium.org>
Date: Wed Apr 05 06:37:56 2017

Revert of More thorough overlapping cursor tests. (patchset #2 id:60001 of https://codereview.chromium.org/2781623008/ )

Reason for revert:
external/wpt/IndexedDB/parallel-overlapping-cursors.html is failing on the win7 webkit bot: https://build.chromium.org/p/chromium.webkit/builders/WebKit%20Win7%20%28dbg%29/builds/9419.

Original issue's description:
> More thorough overlapping cursor tests.
>
> BUG= 705837 
>
> Review-Url: https://codereview.chromium.org/2781623008
> Cr-Commit-Position: refs/heads/master@{#461932}
> Committed: https://chromium.googlesource.com/chromium/src/+/0c187ee3c2b8fc9d0dd81758f892cf6fd0ba4c3f

TBR=jsbell@chromium.org,dmurph@chromium.org,pwnall@chromium.org
# Skipping CQ checks because original CL landed less than 1 days ago.
NOPRESUBMIT=true
NOTREECHECKS=true
NOTRY=true
BUG= 705837 

Review-Url: https://codereview.chromium.org/2803563002
Cr-Commit-Position: refs/heads/master@{#461991}

[delete] https://crrev.com/421f86bb22686a086062ffde46fb746039dd2490/third_party/WebKit/LayoutTests/external/wpt/IndexedDB/interleaved-cursors-support.js
[modify] https://crrev.com/8a1c41840a061c7de4dfe40a4f2f5713645d8800/third_party/WebKit/LayoutTests/external/wpt/IndexedDB/interleaved-cursors.html
[delete] https://crrev.com/421f86bb22686a086062ffde46fb746039dd2490/third_party/WebKit/LayoutTests/external/wpt/IndexedDB/interleaved-overlapping-cursors.html
[delete] https://crrev.com/421f86bb22686a086062ffde46fb746039dd2490/third_party/WebKit/LayoutTests/external/wpt/IndexedDB/parallel-overlapping-cursors.html

Sign in to add a comment