New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 844752 link

Starred by 6 users

Issue metadata

Status: Fixed
Owner:
Closed: May 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug-Regression



Sign in to add a comment

Null-dereference READ in ObtainAndSetContextProvider

Project Member Reported by ClusterFuzz, May 18 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=6133705614295040

Fuzzer: inferno_flicker
Job Type: windows_asan_chrome_no_sandbox
Platform Id: windows

Crash Type: Null-dereference READ
Crash Address: 0x000000000000
Crash State:
  ObtainAndSetContextProvider
  ?RunOnce@?$Invoker@U?$BindState@P6AXV?$OnceCallback@$$A6AX_NPEAVContextProvider@
  base::internal::ReplyAdapter<struct std::pair<class media::GpuVideoAcceleratorFa
  
Sanitizer: address (ASAN)

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6133705614295040

Additional requirements: Requires Gestures

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, May 18 2018

Labels: M-68 Fuzz-Blocker ReleaseBlock-Beta
This crash occurs very frequently on windows platform and is likely preventing the fuzzer inferno_flicker from making much progress. Fixing this will allow more bugs to be found.

Marking this bug as a blocker for next Beta release.

If this is incorrect, please add ClusterFuzz-Wrong label and remove the ReleaseBlock-Beta label.
Cc: brajkumar@chromium.org
Components: Internals>Media
Labels: -Type-Bug -M-68 M-67 Test-Predator-Wrong Type-Bug-Regression
Owner: lethalantidote@chromium.org
Status: Assigned (was: Untriaged)
By comparing the crash state this issue looks similar to  bug 843044 , hence assigning to the same owner for more updates.

lethalantidote@ Could you please take a look in to this issue?

Thanks!

Comment 3 by gov...@chromium.org, May 22 2018

Per comment #1 this bug and  bug 843044  listed at #2 both are reported on M68 Beta. Is this indeed M67 Beta blocker?

Pls note M67 last Beta release is tomorrow, RC cut today @ 1:00 PM PT. We're NOT planning to block tomorrow's last M67 beta for this. Pls let us know ASAP if there is any concern here. Thank you.

Also M67 goes to stable next Tuesday (05/29), Stable RC cut this Thursday (05/24) @ 4:00 PM PT. So if this is indeed M67 blocker, pls land fix to trunk ASAP and request a merge to M67. Thank you.

Comment 4 by gov...@chromium.org, May 22 2018

Cc: liber...@chromium.org
Adding CL reviewer to cc list as well - https://bugs.chromium.org/p/chromium/issues/detail?id=843044#c14.
Labels: -M-67
This should not effect M67 beta launch.
This is only on m68 canary 50/50 finch experiment.

Comment 7 by gov...@chromium.org, May 22 2018

Labels: M-68 Target-68
Thank you  lethalantidote@. Adding M68 milestone per comment #6.
Your bug is tagged as Release block Beta and we are branching in 2 days.Please have a fix ASAP.
Labels: -ReleaseBlock-Beta
This is only turned on for a finch experiment. 
Cc: mlamouri@chromium.org
This is actually affecting Beta 68 launch if we want to have the experiment enabled in 68.
Hmm, it's actually not clear from the clusterfuzz page if this is affecting M68. It mention M66 and M67.  bug 843044  is similar but affects HEAD. I requested a redo of the impact. If it doesn't impact HEAD or M68, we should probably close as this code isn't in production for M66 and M67.
For what I can tell, this is only affecting 66/67. This is what clusterfuzz said on the status page (pending a new task for 2 days so I'm giving up on getting confirmation). I tried locally and it did not crash.

Please reopen if you disagree.
Status: Fixed (was: Assigned)
Project Member

Comment 14 by ClusterFuzz, Jun 1 2018

Labels: Needs-Feedback
ClusterFuzz testcase 6133705614295040 is still reproducing on tip-of-tree build (trunk).

Please re-test your fix against this testcase and if the fix was incorrect or incomplete, please re-open the bug. Otherwise, ignore this notification and add ClusterFuzz-Wrong label.

Sign in to add a comment