New issue
Advanced search Search tips

Issue 903899 link

Starred by 1 user

Issue metadata

Status: Duplicate
Owner:
Closed: Nov 19
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

CHECK failure: !first_party_url_.is_empty() in appcache_host.cc

Project Member Reported by ClusterFuzz, Nov 9

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5199510059614208

Fuzzer: libFuzzer_appcache_fuzzer
Job Type: libfuzzer_chrome_asan_debug
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  !first_party_url_.is_empty() in appcache_host.cc
  content::AppCacheHost::SelectCache
  content::AppCacheBackendImpl::SelectCache
  
Sanitizer: address (ASAN)

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5199510059614208

Issue manually filed by: mmoroz

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
 
Cc: nedwilli...@gmail.com jsb...@chromium.org infe...@chromium.org
Components: Blink>Storage>AppCache
Owner: pwnall@chromium.org
Status: Assigned (was: Untriaged)
We don't have a reliable reproducer for this crash, but it happens a lot, just run the fuzz target for a few seconds / minutes. It also doesn't let us to generate code coverage report for the fuzzer: https://chromium-coverage.appspot.com/reports/606647/linux/metadata/appcache_fuzzer.log

Would really appreciate if this could be prioritized and fixed. The fuzzer is very likely to find some security critical issues, it's important to keep it in a good shape.
Project Member

Comment 2 by ClusterFuzz, Nov 9

Cc: mmoroz@chromium.org
Labels: ClusterFuzz-Auto-CC
Automatically adding ccs based on OWNERS file / target commit history.

If this is incorrect, please add ClusterFuzz-Wrong label.
Mergedinto: 843797
Status: Duplicate (was: Assigned)
Merging this into a bug that does have reliable repro steps.

Sign in to add a comment