Crash in /usr/lib/libc++.1.dylib:x86_64 |
||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5160260462706688 Fuzzer: inferno_layout_test_unmodified Job Type: mac_asan_content_shell Platform Id: mac Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: /usr/lib/libc++.1.dylib:x86_64 /usr/lib/libc++.1.dylib:x86_64 base::FilePath::Append Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=mac_asan_content_shell&range=448729:448967 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv96_JM5QbWCiq1oJZgT_sNnOTi1K-oQQ3QnXE1T-W_2PtjtJ7xys14B3J7xiar1lEV0HqljLpn9SmmqBwP3CWcwBEfA22OfJaDYDx4rKL_rU-H4h9O3FA4eosczpIpY-eSP_BypLK6xKpSecg9rR8ufZfTGym1zaCzAQUJNIyGVR7TTNXTSsRorQ1qmMQnqg4bL7hxVotvqKQIDAdiZO4cmQSjVOcYGXIoWSXgs-2NoKVGPf0Aqe9EU1SRg3IPoximSV_6FhaGlSMb7bvCsuRvA99l5lvetMO3oLNKM53hqLHKW57B-VN5gRi4CqrB9B6hgmaV0vc2FzxDpHf87JuvomIXlvjSNAF1Y6d1sSm6XftZjtPn8?testcase_id=5160260462706688 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 21 2017
Hello, Someone raised a very similar issue (https://bugs.chromium.org/p/chromium/issues/detail?id=713185#c4), but it was subsequently closed. Are these two related? Thanks.
,
Apr 22 2017
As the other issue (https://bugs.chromium.org/p/chromium/issues/detail?id=713185#c4) was fixed/closed, would you please let me know if this issue is also fixed? Please let me know the problem persists. Thanks.
,
Apr 24 2017
jiameng@, i think the problem is still exists. I did a 'REDO TASK', however the CF test case is saying it's not yet fixed. Can you please look into it? Thank you!
,
Apr 30 2017
The error message appears to say the mac-specific CFPasteboardRef didn't exist. Since it only occurred on a mac, I'll need a mac machine to reproduce the error. Meanwhile, is there any chance that this CFPasteboardRef was not properly initialized (or deleted) somewhere else? Thanks.
,
May 11 2017
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/4d916411aa57de16c95e693cf9dd33d7e3bf65ee commit 4d916411aa57de16c95e693cf9dd33d7e3bf65ee Author: jiameng <jiameng@chromium.org> Date: Thu May 11 10:56:14 2017 Initialize test configuration to a default value. BlinkTestRunner::OnSetTestConfiguration should be called to init test_config_ before any method using test_config_ is run. However, this is not always enforced by the test runner/controller as discovered by clusterfuzz (see bug below). Hence this cl initializes test_config_ to a default value to ensure it is never a null ptr. BUG= 714028 Review-Url: https://codereview.chromium.org/2869333002 Cr-Commit-Position: refs/heads/master@{#470913} [modify] https://crrev.com/4d916411aa57de16c95e693cf9dd33d7e3bf65ee/content/shell/common/layout_test.mojom [modify] https://crrev.com/4d916411aa57de16c95e693cf9dd33d7e3bf65ee/content/shell/renderer/layout_test/blink_test_runner.cc
,
May 11 2017
The crash occurred because the test controller did not call a method to properly initialize an object before using it. I've submitted a cl to default initialize the object in case the init method isn't called. My local test run shows the clusterfuzz issue is resolved. Hence I'm closing the ticket now. Thanks.
,
May 12 2017
ClusterFuzz has detected this issue as fixed in range 470896:470927. Detailed report: https://clusterfuzz.com/testcase?key=5160260462706688 Fuzzer: inferno_layout_test_unmodified Job Type: mac_asan_content_shell Platform Id: mac Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: /usr/lib/libc++.1.dylib:x86_64 /usr/lib/libc++.1.dylib:x86_64 base::FilePath::Append Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=mac_asan_content_shell&range=448729:448967 Fixed: https://clusterfuzz.com/revisions?job=mac_asan_content_shell&range=470896:470927 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5160260462706688 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page. |
||
►
Sign in to add a comment |
||
Comment 1 by msrchandra@chromium.org
, Apr 21 2017Labels: M-60 Test-Predator-Correct-CLs
Owner: jiameng@chromium.org
Status: Assigned (was: Untriaged)