Issue metadata
Sign in to add a comment
|
value.isFunctionValue() |
||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6302873694765056 Fuzzer: inferno_twister_custom_bundle Job Type: linux_asan_content_shell_drt Platform Id: linux Crash Type: ASSERT Crash Address: Crash State: value.isFunctionValue() blink::CSSTransformComponent::fromCSSValue blink::CSSTransformValue::fromCSSValue Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_content_shell_drt&range=413791:414128 Minimized Testcase (1.98 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97BrxC_6VC2KPrY2lw1ydf45UduE2zEGm210DR6DsIoNY4X8yQ2LXuY4eM3zgUKvcqYJ51Td_La-mx4yFdTLTIcrGOYBV8YN7aJ2klWbCg_MuicLAx8MHSRLAIEnb8gCrmYdrrcZaGBj3Sq8MRivQs7lPKUHA?testcase_id=6302873694765056 Additional requirements: Requires HTTP Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Dec 17 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by infe...@chromium.org
, Aug 29 2016Status: Duplicate (was: Untriaged)