New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 779370 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 774369
Owner:
please use my google.com address
Closed: Oct 2017
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Windows , Mac
Pri: 1
Type: Bug



Sign in to add a comment

CHECK failure: message->data_num_bytes() < GetConfiguration().max_message_num_bytes in node_cha

Project Member Reported by ClusterFuzz, Oct 28 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=6668147641024512

Fuzzer: miaubiz_svg_fuzzer
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  message->data_num_bytes() < GetConfiguration().max_message_num_bytes in node_cha
  mojo::edk::NodeChannel::WriteChannelMessage
  mojo::edk::NodeChannel::SendChannelMessage
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=508393:508454

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6668147641024512

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Oct 29 2017

Labels: OS-Windows OS-Android OS-Mac
Cc: msrchandra@chromium.org pnangunoori@chromium.org
Labels: Test-Predator-Wrong M-63
Owner: roc...@chromium.org
Status: Assigned (was: Untriaged)
Predator and CL could not provide any possible suspects.
Using the code search for the file, “node_channel.cc” assigning to concern owner from GIT blame.
Suspecting Commit#
https://chromium.googlesource.com/chromium/src/+/0d4eb8a5f8d99d365459af21442cbc7b8648cf66

@rockot -- Could you please look into this issue, kindly reassign if it has nothing to do with your changes.
Thank You.

Comment 3 by roc...@chromium.org, Oct 30 2017

Mergedinto: 774369
Status: Duplicate (was: Assigned)
Project Member

Comment 4 by ClusterFuzz, Nov 1 2017

ClusterFuzz is analyzing your testcase. Developers can follow the progress at https://clusterfuzz.com/testcase?key=5502288792911872.
Project Member

Comment 5 by ClusterFuzz, Nov 1 2017

Labels: Security_Impact-Beta
Detailed report: https://clusterfuzz.com/testcase?key=5502288792911872

Job Type: linux_ubsan_chrome
Crash Type: CHECK failure
Crash Address: 
Crash State:
  message->data_num_bytes() < GetConfiguration().max_message_num_bytes in node_cha
  mojo::edk::NodeChannel::WriteChannelMessage
  mojo::edk::NodeChannel::SendChannelMessage
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=508393:508454

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5502288792911872

See https://github.com/google/clusterfuzz-tools for more information.

Sign in to add a comment