Use-after-poison in blink::ComputePresentationAttributeStyle |
||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5605399970185216 Fuzzer: inferno_webbot Job Type: linux_asan_chrome_media Platform Id: linux Crash Type: Use-after-poison READ 8 Crash Address: 0x7ec2e5b5d6d0 Crash State: blink::ComputePresentationAttributeStyle blink::Element::UpdatePresentationAttributeStyle blink::StyleResolver::MatchAllRules Sanitizer: address (ASAN) Recommended Security Severity: High Regressed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_media&range=535301:535307 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5605399970185216 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Feb 8 2018
Testcase 5605399970185216 is a top crash on ClusterFuzz for windows platform. Please prioritize fixing this crash. Marking this crash as a Beta release blocker. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Feb 8 2018
Automatically assigning owner based on suspected regression changelist https://chromium.googlesource.com/chromium/src/+/6ed531bd5ae325f1964ab2db962c4bf75625c95f (dom: Remove PresentationAttributeCacheCleaner). If this is incorrect, please let us know why and apply the Test-Predator-Wrong-CLs label. If you aren't the correct owner for this issue, please unassign yourself as soon as possible so it can be re-triaged.
,
Feb 8 2018
,
Feb 8 2018
,
Feb 8 2018
,
Feb 8 2018
Seems like this is Regressed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_media&range=535301:535307 (66.0.3344.0:66.0.3344.0). Not sure why ClusterFuzz is adding M65 label to the bug instead of M66. I'm not planning to block M65 beta promotion for this bug. +awhalley@, pls let me know if there is any concern here. Thank you.
,
Feb 9 2018
govind@, we have a fix for c#7. this is due to incorrect milestone calculation on linux, we just used dev milestone for canary (since there is no canary for linux). instead we should be using canary from other platform like win.
,
Feb 9 2018
This crash occurs very frequently on windows platform and is likely preventing the fuzzer inferno_webbot from making much progress. Fixing this will allow more bugs to be found. Marking this bug as a blocker for next Beta release. If this is incorrect, please add ClusterFuzz-Wrong label and remove the ReleaseBlock-Beta label.
,
Feb 9 2018
Thank you inferno@ for clarification at #8. Yeah, pls use canary version of windows/Mac as no canary for Linux.
,
Feb 9 2018
,
Feb 9 2018
Issue 810819 has been merged into this issue.
,
Feb 9 2018
Issue 810870 has been merged into this issue.
,
Feb 9 2018
Revert in progress - https://chromium-review.googlesource.com/c/chromium/src/+/912091.
,
Feb 9 2018
Automatically applying components based on crash stacktrace and information from OWNERS files. If this is incorrect, please apply the Test-Predator-Wrong-Components label.
,
Feb 9 2018
Issue 810915 has been merged into this issue.
,
Feb 10 2018
,
Feb 10 2018
Issue 810995 has been merged into this issue.
,
Feb 10 2018
ClusterFuzz has detected this issue as fixed in range 535922:535929. Detailed report: https://clusterfuzz.com/testcase?key=5605399970185216 Fuzzer: inferno_webbot Job Type: linux_asan_chrome_media Platform Id: linux Crash Type: Use-after-poison READ 8 Crash Address: 0x7ec2e5b5d6d0 Crash State: blink::ComputePresentationAttributeStyle blink::Element::UpdatePresentationAttributeStyle blink::StyleResolver::MatchAllRules Sanitizer: address (ASAN) Recommended Security Severity: High Regressed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_media&range=535301:535307 Fixed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_media&range=535922:535929 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5605399970185216 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Feb 10 2018
ClusterFuzz testcase 5605399970185216 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Feb 10 2018
,
Mar 2 2018
,
Mar 16 2018
,
Mar 16 2018
This bug requires manual review: M66 has already been promoted to the beta branch, so this requires manual review Please contact the milestone owner if you have questions. Owners: cmasso@(Android), cmasso@(iOS), josafat@(ChromeOS), abdulsyed@(Desktop) For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Mar 19 2018
,
Mar 19 2018
Does anything need to be merged here? Looks like revert already landed in #14.
,
May 19 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||||||||||||||||||
►
Sign in to add a comment |
||||||||||||||||||||
Comment 1 by ClusterFuzz
, Feb 8 2018