Issue metadata
Sign in to add a comment
|
CHECK failure: net_error_ != OK in fuzzed_socket.cc |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=4684556224692224 Fuzzer: libFuzzer_net_spdy_session_fuzzer Job Type: libfuzzer_chrome_asan_debug Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: net_error_ != OK in fuzzed_socket.cc base::debug::DebugBreak net::FuzzedSocket::Connect Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan_debug&range=493087:493142 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4684556224692224 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Sep 13 2017
Unable to find the possible suspect using Predator, CL and Code Search. Could some one please look into the issue. Thank You.
,
Oct 1 2017
Automatically applying components based on information from OWNERS files. If this seems incorrect, please apply the Test-Predator-Wrong-Components label.
,
Oct 2 2017
,
Oct 3 2017
I would not classify this as wrong component. If you want more specific component, add the component in https://chromium.googlesource.com/chromium/src/+/661285b9d4dcf79b97c97581dfbe32c3954e7ec4/net/socket/OWNERS
,
Oct 3 2017
,
Oct 3 2017
Here is the Change Log from above CF report. https://chromium.googlesource.com/chromium/src/+log/22ff05c7b4e962b6486f0a1aa4c4f80f7b26d45b..661285b9d4dcf79b97c97581dfbe32c3954e7ec4?pretty=fuller&n=10000 bnc@, can you please look into this change (https://chromium.googlesource.com/chromium/src/+/5bf3f4f0a2defd3227f8d960825da523ceb6ddfa) ? Thank you!
,
Oct 4 2017
I can reproduce it locally. I'm working on it.
,
Oct 5 2017
Bisect points to https://crrev.com/c/608624. But it feels like it's a bug in FuzzedSocket. Still investigating.
,
Oct 24 2017
For more information, please see https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md. The link referenced in the description is no longer valid. (bulk edit)
,
Jan 8 2018
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/2e4722c2d6815b73d3b67da3e69eebc7bd3df1a7 commit 2e4722c2d6815b73d3b67da3e69eebc7bd3df1a7 Author: Bence Béky <bnc@chromium.org> Date: Mon Jan 08 17:05:00 2018 Do not call StreamSocket::Connect from MockSSLClientSocket::Connect(). FuzzedSocket::Connect() does not support multiple calls. In fact, MockSSLClientSocket takes a connected socket, so it should not call Connect() on it. This CL fixes that, and adds a DCHECK that the socket is already connected. Note that HttpNetworkTransactionTest.ProxyTunnelGetHangup fails the new DCHECK, because ERR_TEST_PEER_CLOSE_AFTER_NEXT_MOCK_READ closes down the socket in a weird way that can never happen as a result of actual network data. Thus I am removing this MockRead. Reading the EOF closes the socket anyway and makes sure the test is doing the right thing. Bug: 754121 Change-Id: Iacaa507edf41a611e1595d1e333d93caa285c260 Reviewed-on: https://chromium-review.googlesource.com/852572 Reviewed-by: Matt Menke <mmenke@chromium.org> Commit-Queue: Bence Béky <bnc@chromium.org> Cr-Commit-Position: refs/heads/master@{#527652} [modify] https://crrev.com/2e4722c2d6815b73d3b67da3e69eebc7bd3df1a7/net/http/http_network_transaction_unittest.cc [modify] https://crrev.com/2e4722c2d6815b73d3b67da3e69eebc7bd3df1a7/net/socket/socket_test_util.cc
,
Jan 8 2018
,
Jan 9 2018
ClusterFuzz has detected this issue as fixed in range 527649:527661. Detailed report: https://clusterfuzz.com/testcase?key=4684556224692224 Fuzzer: libFuzzer_net_spdy_session_fuzzer Job Type: libfuzzer_chrome_asan_debug Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: net_error_ != OK in fuzzed_socket.cc net::FuzzedSocket::Connect net::MockSSLClientSocket::Connect Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan_debug&range=493087:493142 Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan_debug&range=527649:527661 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4684556224692224 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jan 9 2018
ClusterFuzz testcase 4684556224692224 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by msrchandra@chromium.org
, Aug 10 2017