Crash in blink::SimpleFontData::isTextOrientationFallbackOf |
|||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5672337414553600 Fuzzer: ochang_domfuzzer Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000c8 Crash State: blink::SimpleFontData::isTextOrientationFallbackOf blink::ShapeResult::fallbackFonts blink::CachingWordShaper::width Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=411257:411277 Minimized Testcase (1.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv9433cRhE_sxuqIsUMdOsTHP4udvzNzkCNrJckGEHog7Eo47qL0WsBm3Ye_IrX9_B2d_xNsCJCBuvYgt4awgejla_d542oXxW_9tNCsOtEr-qr3yj4EN2PBzT0Rkzp7fQB_-jtLaPejAyiJfwLfuIHzgdM-hbw?testcase_id=5672337414553600 Issue manually filed by: mmohammad See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Aug 12 2016
drott@, is this the primaryFont nullptr problem?
,
Aug 12 2016
I don't think we have that on Linux so much, that's mostly Windows. I can try to take a look. Perhaps something to do with the "font-style: italic; writing-mode: vertical-lr;" from the test case.
,
Aug 12 2016
> Job Type: linux_asan_chrome_v8_arm mmohammad@, is this reproducible on non-arm?
,
Aug 14 2016
ClusterFuzz has detected this issue as fixed in range 411868:411875. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5672337414553600 Fuzzer: ochang_domfuzzer Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000c8 Crash State: blink::SimpleFontData::isTextOrientationFallbackOf blink::ShapeResult::fallbackFonts blink::CachingWordShaper::width Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=411257:411277 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=411868:411875 Minimized Testcase (1.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv9433cRhE_sxuqIsUMdOsTHP4udvzNzkCNrJckGEHog7Eo47qL0WsBm3Ye_IrX9_B2d_xNsCJCBuvYgt4awgejla_d542oXxW_9tNCsOtEr-qr3yj4EN2PBzT0Rkzp7fQB_-jtLaPejAyiJfwLfuIHzgdM-hbw?testcase_id=5672337414553600 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Aug 14 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||
►
Sign in to add a comment |
|||||
Comment 1 by mmohammad@chromium.org
, Aug 11 2016Owner: kojii@chromium.org
Status: Assigned (was: Untriaged)