New issue
Advanced search Search tips

Issue 594469 link

Starred by 0 users

Issue metadata

Status: Fixed
Owner:
Closed: Mar 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Regression



Sign in to add a comment

Crash in blink::Node::assignedSlot

Project Member Reported by ClusterFuzz, Mar 14 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6692923904622592

Fuzzer: noel-image-surku
Job Type: linux_asan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x000000000010
Crash State:
  blink::Node::assignedSlot
  blink::SlotScopedTraversal::isSlotScoped
  blink::FocusController::advanceFocusInDocumentOrder
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=380105:380830

Minimized Testcase (0.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95E3kbvkim-UBSy9pDV16r4Zzt8d4blMrjwl4z4TkLXoa5QsIzzd9kvOHpqX3j81MSGJ6cIorSPWV7RxRZNq0kOJaoos_vOplmJSe6-M6t97EH2av6tDC9eROfKt6VDIjDE9OWvpHvkLpiFO0C7bYh65b1npQ

Additional requirements: Requires Gestures

Filer: ajha

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 

Comment 1 by ajha@chromium.org, Mar 14 2016

Labels: -Type-Bug findit-wrong M-50 Te-Logged Type-Bug-Regression
Owner: yuzus@chromium.org
Status: Assigned (was: Available)
Suspected CLs	No CL in the regression range changes the crashed files. The result is the blame information.

Author: mjs@apple.com
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/554c7634cddfec7925865257d362fa718c34ac3a
Time: Thu May 06 22:41:15 2010
The CL last changed line 738 of file Node.h, which is stack frame 0.

Author: morrita@google.com
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/55acae1c2d27b32174a87280e67c2fad5513fd70
Time: Tue Nov 27 08:49:23 2012
The CL last changed line 297 of file Node.h, which is stack frame 1.

Author: esprehn@chromium.org
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/09e6bebd4291056d2ba3e8b8ca8f1117ca1524b8
Time: Sat Dec 22 00:24:18 2012
The CL last changed line 298 of file Node.h, which is stack frame 2.

Author: kenneth.r.christiansen@intel.com
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/cc604a057cdae70220ad0c36095d5decbbd27980
Time: Thu Oct 23 12:24:00 2014
The CL last changed line 863 of file Node.h, which is stack frame 3.

Author: darin@apple.com
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/a857f5b7879ff21e775308154b115f7939a2784a
Time: Fri Oct 15 18:30:37 2010
The CL last changed line 755 of file Element.h, which is stack frame 4.

Author: hayato
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/fa296ea635357362e48bd203888ae44854d8e748
Time: Tue Jan 12 03:29:07 2016
The CL last changed line 1003 of file Node.cpp, which is stack frame 5.

Author: rune
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/d20f8d9a716b2f64a0f53f7be939d7ab68768ac7
Time: Mon Feb 22 07:29:48 2016
The CL last changed line 2267 of file Node.cpp, which is stack frame 6.

Suspected Component: chromium
Suspected Cr- Label: Cr-Blink-DOM
======================================================
None of the above changes from the find it looks related.

Based on the code search on 'SlotScopedTraversal.cpp', suspecting: https://codereview.chromium.org/1707443003

yuzuchan@: Could you please take a look at this.

Thank you!
Project Member

Comment 2 by ClusterFuzz, Mar 16 2016

ClusterFuzz has detected this issue as fixed in range 381067:381276.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6692923904622592

Fuzzer: noel-image-surku
Job Type: linux_asan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x000000000010
Crash State:
  blink::Node::assignedSlot
  blink::SlotScopedTraversal::isSlotScoped
  blink::FocusController::advanceFocusInDocumentOrder
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=380105:380830
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=381067:381276

Minimized Testcase (0.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95E3kbvkim-UBSy9pDV16r4Zzt8d4blMrjwl4z4TkLXoa5QsIzzd9kvOHpqX3j81MSGJ6cIorSPWV7RxRZNq0kOJaoos_vOplmJSe6-M6t97EH2av6tDC9eROfKt6VDIjDE9OWvpHvkLpiFO0C7bYh65b1npQ

Additional requirements: Requires Gestures

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Comment 3 by ajha@chromium.org, Mar 16 2016

Status: Fixed (was: Assigned)
Marking this Fixed as per C#2.
Project Member

Comment 4 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment