New issue
Advanced search Search tips

Issue 615338 link

Starred by 0 users

Issue metadata

Status: Verified
Owner: ----
Closed: Jul 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 2
Type: Bug



Sign in to add a comment

REDOCF: FontSizeDelta command with unusual HTML crashes

Project Member Reported by ClusterFuzz, May 27 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5491431250853888

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_asan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000010
Crash State:
  blink::ApplyStyleCommand::applyRelativeFontStyleChange
  blink::ApplyStyleCommand::doApply
  blink::CompositeEditCommand::apply
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=144946:145047

Minimized Testcase (0.83 Kb): https://cluster-fuzz.appspot.com/download/AMIfv974MT-H7B3THQAU7UhRdnQoteDgGVSYl5sVx9m_FGIkRhZmDpEBvWKgW6TTJ4eobnUyWZUdWtN0YyZY_Btw7FfQMtkiVvHQeVRCn_WOiGE4Oh63cSGs3ArFnOxeQwIXyOx-dYNo321yJRQNqwdnCXTAQnrgMg

Filer: nyerramilli

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: nyerramilli@chromium.org
Components: Tools>Test>FindIt>WrongResult Blink>DOM
Labels: findit-wrong Te-Logged M-51
Owner: yosin@chromium.org
Status: Assigned (was: Available)
using codesearch, seeing some changes to 'ApplyStyleCommand.cpp' in 
https://chromium.googlesource.com/chromium/src/+log/master/third_party/WebKit/Source/core/editing/commands/ApplyStyleCommand.cpp

this might be dupe of https://bugs.chromium.org/p/chromium/issues/detail?id=609656.

yosin@ could you please check and help.

providing find it results for internal purpose:
Suspected CLs	No CL in the regression range changes the crashed files. The result is the blame information.

Author: mjs@apple.com
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/554c7634cddfec7925865257d362fa718c34ac3a
Time: Thu May 06 22:41:15 2010
The CL last changed line 744 of file Node.h, which is stack frame 0.

Author: commit-queue@webkit.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/a617e8a70e2f33152f9b00a7f6e86cd8ba8a29b5
Time: Sat Apr 21 00:18:20 2012
The CL last changed line 244 of file Node.h, which is stack frame 1.

Author: darin@apple.com
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/a631e609095b01bf92e43c22ed40b05aaa68d50b
Time: Mon Oct 18 19:52:27 2010
The CL last changed line 307 of file ContainerNode.h, which is stack frame 2.

Author: ch.dumez@samsung.com
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/77df0cd163cc0e13196aadf3a188f5991ab3508a
Time: Fri Feb 21 23:18:01 2014
The CL last changed line 226 of file Node.h, which is stack frame 3.

Author: ch.dumez@samsung.com
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/b76f46669447f9b9c0709da786fb4f69cb641feb
Time: Mon Jul 28 22:42:25 2014
The CL last changed line 263 of file NodeTraversal.h, which is stack frame 4.

Author: ch.dumez@samsung.com
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/5c77c7d2869ec1921bed356e8f7afa5ada7f0ee6
Time: Thu Feb 20 07:38:48 2014
The CL last changed line 53 of file NodeTraversal.h, which is stack frame 5.

Author: ch.dumez@samsung.com
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/f6a06fcf932b61f07b84ceead261fddce5790538
Time: Wed Feb 26 02:30:18 2014
The CL last changed line 398 of file ApplyStyleCommand.cpp, which is stack frame 6.

Suspected Project: chromium-blink
Suspected Component: Blink>DOM


Comment 2 by yosin@chromium.org, Jun 10 2016

Components: Blink>Editing>Command
Labels: -OS-Linux -Pri-1 OS-All Pri-2
Owner: ----
Status: Available (was: Assigned)
Summary: REDOCF: FontSizeDelta command with unusual HTML crashes (was: Crash in blink::ApplyStyleCommand::applyRelativeFontStyleChange)
Lower to Pri-2, since real world usage of FontSizeDelta command is low.

Not repro on ToT.


Comment 3 by tkent@chromium.org, Jul 5 2016

Components: -Blink>DOM
Project Member

Comment 4 by ClusterFuzz, Jul 6 2016

ClusterFuzz has detected this issue as fixed in range 403746:403751.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5491431250853888

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_asan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000010
Crash State:
  blink::ApplyStyleCommand::applyRelativeFontStyleChange
  blink::ApplyStyleCommand::doApply
  blink::CompositeEditCommand::apply
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=268656:269696
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=403746:403751

Minimized Testcase (2.62 Kb): https://cluster-fuzz.appspot.com/download/AMIfv972hMVfjIqNChDk_xLZWFvLhmA5KoisL7jENfrJnSuR1e0RVDcRKCPfjOBGb8jYQ3A4nTj65txItxzkCQwLlntmIEwNq_ZjfNZ2vmUf48Ntwm6K_3hLfPhK4EvEs_6b29-dZnyFwQguVPdtL2eU4dUP81f3Pw?testcase_id=5491431250853888

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by ClusterFuzz, Jul 6 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Available)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Components: -Tools>Test>FindIt>WrongResult
Labels: Test-Predator-Wrong
Project Member

Comment 7 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment