Null-dereference in content::BlinkTestController::OnLayoutTestRuntimeFlagsChanged |
|||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5388534080077824 Fuzzer: inferno_layout_test_unmodified Job Type: linux_ubsan_vptr_content_shell_drt Platform Id: linux Crash Type: Null-dereference Crash Address: 0x000000000000 Crash State: content::BlinkTestController::OnLayoutTestRuntimeFlagsChanged _ZN3IPC8MessageTI52LayoutTestHostMsg_LayoutTestRuntimeFlagsChanged_MetaNSt3__15t content::LayoutTestMessageFilter::OnMessageReceived Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_content_shell_drt&range=495811:495812 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5388534080077824 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Sep 12 2017
This is definitely in no way related to my change? My change is just changing the TestExpectations for LayoutTests -- a plain text file which is used to determine what tests are okay to fail... Did you happen to get the wrong CLs?
,
Sep 19 2017
Using Code Search for the file, "OnLayoutTestRuntimeFlagsChanged" assigning to the concern owner. Suspecting Commit# https://chromium.googlesource.com/chromium/src/+/607cb1475d625041f23200d3002c448e06239570 @jsbell -- Could you please look into the issue, kindly re-assign if this is not related to your changes. Thank You.
,
Sep 19 2017
Hrm, I just added a DCHECK to make sure the message was happening on the right thread. So likely not my change. But I'm not finding any likely candidates either. No luck bisecting?
,
Sep 28 2017
Test only crash in BlinkTestController.
,
Nov 13 2017
ClusterFuzz testcase 5388534080077824 is flaky and no longer crashes, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
|||||
►
Sign in to add a comment |
|||||
Comment 1 by msrchandra@chromium.org
, Sep 12 2017Labels: Test-Predator-Wrong
Owner: tansell@chromium.org
Status: Assigned (was: Untriaged)