New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 640475 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Jan 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 2
Type: Bug



Sign in to add a comment

Direct-leak in blink::CSSSelectorList::adoptSelectorVector

Project Member Reported by ClusterFuzz, Aug 24 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6198715478179840

Fuzzer: afl_renderer_fuzzer
Job Type: afl_chrome_asan
Platform Id: linux

Crash Type: Direct-leak
Crash Address: 
Crash State:
  blink::CSSSelectorList::adoptSelectorVector
  blink::CSSSelectorParser::consumeComplexSelectorList
  blink::CSSSelectorParser::parseSelector
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=408200:408315

Minimized Testcase (0.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95GmnmHYztgoAN5uDi-lhP0e3ivvNQ23y63YktImW0r5VHq7IdsU8535dVn5-gOB_7wZb1ox1Lk1-1z8qgqi7lTCqbW9lRxSE4W0VQRXQv_A0vmDidsxq2H5gH1ryYfEu7HEdS879q9KrY1wBFBVpMC43O7xw?testcase_id=6198715478179840

Issue manually filed by: alancutter

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Components: Blink>CSS
Labels: -OS-Linux OS-All
Status: Available (was: Untriaged)
Looks like we're doing crazy stuff with memory here. Either needs rewriting or have suppressions added.
Project Member

Comment 2 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Cc: msrchandra@chromium.org
Labels: Test-Predator-Wrong-CLs
Owner: hayato@chromium.org
Status: Assigned (was: Available)
Unable to find the possible suspect using CL and Find it.
Using Code Search for the file, "CSSSelectorList.cpp" assigning to the concern owner.

Suspecting Commit#
https://chromium.googlesource.com/chromium/src/+/78be6354d3b13dff165e2715957bab3a6d158098

@hayato -- Could you please look into the issue, kindly re-assign if this is not related to your changes.
Thank You.
Project Member

Comment 4 by ClusterFuzz, Jan 15 2017

Status: WontFix (was: Assigned)
ClusterFuzz testcase 6198715478179840 is flaky and no longer reproduces, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment