New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 846775 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Jun 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Null-dereference READ in blink::IdlenessDetector::Shutdown

Project Member Reported by ClusterFuzz, May 25 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5152814607892480

Fuzzer: j00ru_htmlcss_fuzz
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Null-dereference READ
Crash Address: 0x000000000000
Crash State:
  blink::IdlenessDetector::Shutdown
  blink::LocalFrame::Detach
  blink::HTMLFrameOwnerElement::DisconnectContentFrame
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=561772:561773

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5152814607892480

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, May 25 2018

Components: Blink>Internals Blink>Loader
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Project Member

Comment 2 by ClusterFuzz, May 25 2018

Labels: Test-Predator-Auto-Owner
Owner: tapted@chromium.org
Status: Assigned (was: Untriaged)
Automatically assigning owner based on suspected regression changelist https://chromium.googlesource.com/chromium/src/+/8bfe06b77c234470d1edb6b39f9d95d4a04f5a9e (Mark fast/webgl/webgl-composite-modes.html flaky).

If this is incorrect, please let us know why and apply the Test-Predator-Wrong-CLs label. If you aren't the correct owner for this issue, please unassign yourself as soon as possible so it can be re-triaged.

Comment 3 by tapted@chromium.org, May 29 2018

Owner: ----
Status: Untriaged (was: Assigned)
That CL only changed TestExpectations . I've re-run some tasks in clusterfuzz.
Project Member

Comment 4 by ClusterFuzz, May 29 2018

Labels: -Reproducible Unreproducible
ClusterFuzz testcase 5152814607892480 appears to be flaky, updating reproducibility label.
Cc: brajkumar@chromium.org
Labels: Test-Predator-Wrong CF-NeedsTriage
Unable to find actual suspect through code search and also observing no suspected CL's under regression range, hence adding appropriate label and requesting someone from blink team to look in to this issue.

Thanks!
Labels: -Pri-1 Pri-2
Lowering the priority since marked as Unreproducible.
Project Member

Comment 7 by ClusterFuzz, Jun 12 2018

Status: WontFix (was: Untriaged)
ClusterFuzz testcase 5152814607892480 is flaky and no longer crashes, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment