Issue metadata
Sign in to add a comment
|
Crash in blink::PersistentBase<blink::DummyGCBase, |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5788486597869568 Fuzzer: inferno_layout_test_fuzzer Job Type: linux_asan_chrome_mp Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x7ecd931a1928 Crash State: blink::PersistentBase<blink::DummyGCBase, blink::CrossThreadPersistentRegion::PrepareForThreadStateTermination blink::ThreadState::RunTerminationGC Sanitizer: address (ASAN) Recommended Security Severity: Medium Regressed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_mp&range=473072:473106 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5788486597869568 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Oct 22 2017
,
Oct 22 2017
This is a serious security regression. If you are not able to fix this quickly, please revert the change that introduced it. If this doesn't affect a release branch, or has not been properly classified for severity, please update the Security_Impact or Security_Severity labels, and remove the ReleaseBlock label. To disable this altogether, apply ReleaseBlock-NA. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 22 2017
,
Oct 23 2017
,
Oct 30 2017
[Bulk Edit] URGENT - PTAL. M63 Stable promotion is coming soon and your bug is labelled as Stable ReleaseBlock, pls make sure to land the fix and get it merged into the release branch ASAP. Thank you.
,
Nov 2 2017
keishi@ -- can you please help triage this and find the right owner quickly? thanks.
,
Nov 2 2017
,
Nov 3 2017
+awhalley@, PTAL and expedite the fix if it is indeed M63 Stable blocker. Thank you.
,
Nov 4 2017
keishi: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Nov 6 2017
M63 Stable promotion is coming soon and your bug is labelled as Stable ReleaseBlock, pls make sure to land the fix and request a merge to M63 ASAP. Thank you.
,
Nov 7 2017
,
Nov 8 2017
Not reproducible locally even when using "clusterfuzz reproduce" Threre has been a number of similar clusterfuzz reports in the past and I have tried fixing them. https://bugs.chromium.org/p/chromium/issues/list?can=1&q=PersistentBase++DummyGCBase&colspec=ID+Pri+M+Stars+ReleaseBlock+Component+Status+Owner+Summary+OS+Modified&x=m&y=releaseblock&cells=ids But almost no actual reports from the wild so I will keep looking but I don't think it should block a release. https://crash.corp.google.com/browse?q=product.name%20CONTAINS%20%27Chrome%27%20OMIT%20RECORD%20IF%20SUM(CrashedStackTrace.StackFrame.FunctionName%3D%27blink%3A%3ACrossThreadPersistentRegion%3A%3AprepareForThreadStateTermination(blink%3A%3AThreadState*)%27)%20%3D%200&sql_dialect=dremelsql&ignore_case=false&enable_rewrite=true&omit_field_name=CrashedStackTrace.StackFrame.FunctionName&omit_field_value=blink%3A%3ACrossThreadPersistentRegion%3A%3AprepareForThreadStateTermination(blink%3A%3AThreadState*)&omit_field_opt=%3D#samplereports https://crash.corp.google.com/browse?q=product.name%20CONTAINS%20%27Chrome%27%20OMIT%20RECORD%20IF%20SUM(CrashedStackTrace.StackFrame.FunctionName%20CONTAINS%20%27DummyGCBase%27)%20%3D%200&sql_dialect=dremelsql&ignore_case=false&enable_rewrite=false&omit_field_name=CrashedStackTrace.StackFrame.FunctionName&omit_field_value=blink%3A%3ACrossThreadPersistentRegion%3A%3AprepareForThreadStateTermination(blink%3A%3AThreadState*)&omit_field_opt=%3D
,
Nov 8 2017
This is a serious security regression. If you are not able to fix this quickly, please revert the change that introduced it. If this doesn't affect a release branch, or has not been properly classified for severity, please update the Security_Impact or Security_Severity labels, and remove the ReleaseBlock label. To disable this altogether, apply ReleaseBlock-NA. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Nov 9 2017
keishi@ - thanks for looking into this. Note that for security issues it doesn't matter if there haven't been any reports in the wild - we're primarily interested in preventing an active exploitation of the bug, rather than the stability issue.
,
Nov 9 2017
This is a serious security regression. If you are not able to fix this quickly, please revert the change that introduced it. If this doesn't affect a release branch, or has not been properly classified for severity, please update the Security_Impact or Security_Severity labels, and remove the ReleaseBlock label. To disable this altogether, apply ReleaseBlock-NA. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Nov 10 2017
,
Nov 14 2017
ClusterFuzz has detected this issue as fixed in range 511144:511192. Detailed report: https://clusterfuzz.com/testcase?key=5788486597869568 Fuzzer: inferno_layout_test_fuzzer Job Type: linux_asan_chrome_mp Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x7ecd931a1928 Crash State: blink::PersistentBase<blink::DummyGCBase, blink::CrossThreadPersistentRegion::PrepareForThreadStateTermination blink::ThreadState::RunTerminationGC Sanitizer: address (ASAN) Recommended Security Severity: Medium Regressed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_mp&range=510290:510324 Fixed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_mp&range=511144:511192 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5788486597869568 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 14 2017
ClusterFuzz testcase 5788486597869568 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Nov 15 2017
Re c#13, I've also tried to reproduce this locally and haven't succeeded. After that, I've kicked off Progression task on CF testcase and now it's marked as fixed. Not sure why the fix was not recognized before. The fix range points to the revision landed ~20 days ago: https://chromium.googlesource.com/chromium/src/+log/75b1c3aed7e1265eab65c1fc5516ca5cfda59284..5f207b6db7148720c335155fe1a89a276e256af9?pretty=fuller&n=10000 I'll file a separate bug to investigate that on CF side.
,
Nov 15 2017
,
Feb 21 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Mar 27 2018
|
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by ClusterFuzz
, Oct 21 2017Labels: Test-Predator-AutoComponents