Issue metadata
Sign in to add a comment
|
Use-of-uninitialized-value in test_runner::TestRunnerForSpecificView::Reset |
||||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5291756706070528 Fuzzer: ochang_domfuzzer Job Type: linux_msan_content_shell_drt Platform Id: linux Crash Type: Use-of-uninitialized-value Crash Address: Crash State: test_runner::TestRunnerForSpecificView::Reset test_runner::WebViewTestProxyBase::Reset test_runner::TestInterfaces::ResetAll Sanitizer: memory (MSAN) Recommended Security Severity: Medium Regressed: https://clusterfuzz.com/revisions?job=linux_msan_content_shell_drt&range=390302:390312 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5291756706070528 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Sep 21 2017
,
Sep 21 2017
,
Oct 1 2017
Automatically applying components based on information from OWNERS files. If this seems incorrect, please apply the Test-Predator-Wrong-Components label.
,
Oct 1 2017
,
Oct 5 2017
dmazzoni: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 19 2017
dmazzoni: Uh oh! This issue still open and hasn't been updated in the last 28 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Nov 7 2017
Automatically applying components based on crash stacktrace and information from OWNERS files. If this is incorrect, please apply the Test-Predator-Wrong-Components label.
,
Nov 30 2017
dmazzoni: This bug is pretty old, and we'd like to get it out of the security triage queue. Can you please confirm that this bug only appears in the test runner, and not in production Chrome? If so, we can remove it from our queue. Thank you!
,
Dec 7 2017
,
Dec 18 2017
Unfortunately I'm unable to reproduce this bug locally. I did an MSAN build and then tried to run it like this: out/Release/content_shell --run-layout-test third_party/WebKit/LayoutTests/clusterfuzz-testcase-5291756706070528.html I do agree that the stack trace points to a bug in test_runner, which is not severe at all. It also doesn't look like an area I'm familiar with. In general MSAN needs some love, it's way too difficult to reproduce MSAN bugs, compared to ASAN for example - see crbug.com/786416
,
Jan 2 2018
ochang: I'm wondering if you can dig into this one a bit, since it's your fuzzer and since you might have some insight into MSan reproducibility problems?
,
Jan 16 2018
Oops, missed this one in vacation backlog, sorry. CF seems to have trouble reproducing this one too, but the stack looks similar to bug 773821 which is a reproducible bad cast (but marked non-security because it's likely a bug in the test runner).
,
May 26 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by palmer@chromium.org
, Sep 20 2017Owner: dmazz...@chromium.org
Status: Assigned (was: Untriaged)