Null-dereference READ in blink::V8Window::getComputedAccessibleNodeMethodCallback |
||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5385524223934464 Fuzzer: inferno_twister Job Type: mac_asan_content_shell Platform Id: mac Crash Type: Null-dereference READ Crash Address: 0x000000000050 Crash State: blink::V8Window::getComputedAccessibleNodeMethodCallback v8::internal::FunctionCallbackArguments::Call v8::internal::MaybeHandle<v8::internal::Object> v8::internal::HandleApiCallHelpe Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=mac_asan_content_shell&range=564194:564214 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5385524223934464 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Jun 11 2018
Failed to reproduce on linux. On mac, I can reproduce the segfault when I download the fresh build that clusterfuzz used, extract it and run. But only once :/ All subsequent runs succeed. I need to remove the extracted directory and extract again to make it fail again. This is the first time I have this. It probably means that the bug is timing-dependent, and the timing is just a bit different on the first run. I verified that no files in the extracted folder are modified beside the content_shell.log and Info.plist. Any help how to triage this further is appreciated.
,
Jun 14 2018
ClusterFuzz has detected this issue as fixed in range 566744:566753. Detailed report: https://clusterfuzz.com/testcase?key=5385524223934464 Fuzzer: inferno_twister Job Type: mac_asan_content_shell Platform Id: mac Crash Type: Null-dereference READ Crash Address: 0x000000000050 Crash State: blink::V8Window::getComputedAccessibleNodeMethodCallback v8::internal::FunctionCallbackArguments::Call v8::internal::MaybeHandle<v8::internal::Object> v8::internal::HandleApiCallHelpe Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=mac_asan_content_shell&range=564194:564214 Fixed: https://clusterfuzz.com/revisions?job=mac_asan_content_shell&range=566744:566753 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5385524223934464 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jun 14 2018
ClusterFuzz testcase 5385524223934464 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||
►
Sign in to add a comment |
||
Comment 1 by ClusterFuzz
, Jun 7 2018Labels: Test-Predator-Auto-Components