New issue
Advanced search Search tips

Issue 636210 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Dec 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug



Sign in to add a comment

Crash in blink::LazyLineBreakIterator::LazyLineBreakIterator

Project Member Reported by ClusterFuzz, Aug 10 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5649468232040448

Fuzzer: bj_broddelwerk
Job Type: windows_asan_chrome_no_sandbox
Platform Id: windows

Crash Type: UNKNOWN READ
Crash Address: 0x00000000
Crash State:
  blink::LazyLineBreakIterator::LazyLineBreakIterator
  blink::BreakingContext::handleText
  blink::LineBreaker::nextLineBreak
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_asan_chrome_no_sandbox&range=410634:410785

Minimized Testcase (0.07 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv97VMFB5qq5YE7_fdUXTL7uUcbhOnFOs9RkLMlM2Ezac5d8DdoR1BAT7l7HvzrjVGaU4qorAGHwaUP3H4vbU_drQ_SS9KICDdjNLV0cyHA8FM3rF9OZ2p4lRYbVbr0aRuIbDmt9LOvol912z50oSbVYy_tTzZw?testcase_id=5649468232040448
<style>
*{word-break:break-all;</style>
<ruby>
<textarea>
</textarea>



Issue manually filed by: nyerramilli

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: nyerramilli@chromium.org
Components: Tools>Test>FindIt>NoResult
Labels: M-54 findit-wrong Te-Logged
Owner: wangxianzhu@chromium.org
Status: Assigned (was: Untriaged)
seeing some changes to 'LayoutBlockFlowLine.cpp' in 
https://chromium.googlesource.com/chromium/src/+/bdd41f4e784486fd7522793283cb5c376a057f0a

wangxianzhu @, Could you please check the above issue & help us in finding an owner it its not yours.


note: there is no information from findit
Components: Blink>Layout
Owner: ----
Status: Untriaged (was: Assigned)

Comment 3 by e...@chromium.org, Aug 12 2016

Cc: kojii@chromium.org
Labels: -Pri-1 Pri-2
Status: Available (was: Untriaged)
Project Member

Comment 4 by ClusterFuzz, Aug 12 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5500708373921792

Fuzzer: bj_broddelwerk
Job Type: windows_asan_chrome_no_sandbox
Platform Id: windows

Crash Type: UNKNOWN READ
Crash Address: 0x00000000
Crash State:
  blink::LazyLineBreakIterator::LazyLineBreakIterator
  blink::BreakingContext::handleText
  blink::LineBreaker::nextLineBreak
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_asan_chrome_no_sandbox&range=411432:411522

Minimized Testcase (0.17 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv947xATyU2c94s1MLGxv1qnScqrbWBXsRRkF4LofPjg-OzdmRcsQzspw-N8tmfp-0gDnzljhtTPg_Z3BuC57WsobjENbhvlDD4cfFkgAcHdkycd8zcePUz8F4IBZpbxS35UdcsN_NttJhkc00BmC7iEK4xlhCA?testcase_id=5500708373921792
<style>
.CLASS13{-webkit-line-align:initial;word-break:break-all;}
</style>
<body class="CLASS13 CLASS1">
<button class="CLASS14" disabled="disabled"</svg>
<select>
</select>



Issue manually filed by: mmohammad

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Components: -Tools>Test>FindIt>NoResult
Project Member

Comment 6 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 7 by ClusterFuzz, Dec 22 2016

Status: WontFix (was: Available)
ClusterFuzz testcase 5500708373921792 is flaky and no longer reproduces, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment