New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 629744 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 629034
Owner:
Closed: Aug 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug-Regression



Sign in to add a comment

Undefined-shift in double WTF::toDoubleType<unsigned short,

Project Member Reported by ClusterFuzz, Jul 20 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6371494179635200

Fuzzer: inferno_webbot
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  double WTF::toDoubleType<unsigned short,
  blink::CSSTokenizerInputStream::getDouble
  blink::CSSTokenizer::consumeNumber
  

Minimized Testcase (0.06 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv97bOsNckWGAbPezxn1kDlyF5intjN_sATuBvBwlFHzF6l7dfqVcmreANWCSslGkBbvecBexF-fWBtyMFkofGfxqy9rJ9ewsCW691rbhgwbIXz4KxQfDYVwlh6yL1tZY5hJHNUaTNCocGnokynX4szuRI96-sg?testcase_id=6371494179635200
<script>
window.location = "http://ekiworld.net";</script>


Filer: shans

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Components: Blink>CSS
Status: Untra (was: Available)
Status: Untriaged (was: Untra)

Comment 3 by suzyh@chromium.org, Jul 21 2016

Labels: -Pri-1 -Type-Bug Pri-2 Type-Bug-Regression
Owner: timloh@chromium.org
Status: Assigned (was: Untriaged)
Probably same as  issue 629742 ? Need to investigate website http://ekiworld.net

Comment 4 by f...@opera.com, Jul 21 2016

Labels: -ClusterFuzz Clusterfuzz
A quick search for <a bunch of zeros> (by guided search) found:

z-index:100000000000000000000000000000000000000000000000000000000000;

which I think fits the bill. We started a collection of these over in  issue 629034 , so feel free to dupe if the error is (roughly) this:

../../third_party/WebKit/Source/wtf/dtoa/strtod.cc:271:15: runtime error: shift exponent 63 is too large for 32-bit type int
Mergedinto: 629034
Status: Duplicate (was: Assigned)
Project Member

Comment 6 by ClusterFuzz, Sep 27 2016

ClusterFuzz has detected this issue as fixed in range 407167:409418.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6371494179635200

Fuzzer: inferno_webbot
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  double WTF::toDoubleType<unsigned short,
  blink::CSSTokenizerInputStream::getDouble
  blink::CSSTokenizer::consumeNumber
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=370022:370027
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=407167:409418

Minimized Testcase (0.06 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv97bOsNckWGAbPezxn1kDlyF5intjN_sATuBvBwlFHzF6l7dfqVcmreANWCSslGkBbvecBexF-fWBtyMFkofGfxqy9rJ9ewsCW691rbhgwbIXz4KxQfDYVwlh6yL1tZY5hJHNUaTNCocGnokynX4szuRI96-sg?testcase_id=6371494179635200
<script>
window.location = "http://ekiworld.net";</script>


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 7 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment