New issue
Advanced search Search tips

Issue 648156 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Sep 2016
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in blink::PositionTemplate<blink::EditingAlgorithm<blink::NodeTraversal> >::lastPos

Project Member Reported by ClusterFuzz, Sep 19 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6733388528746496

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_lsan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000010
Crash State:
  blink::PositionTemplate<blink::EditingAlgorithm<blink::NodeTraversal> >::lastPos
  blink::PositionTemplate<blink::EditingAlgorithm<blink::NodeTraversal> > blink::l
  blink::lastEditablePositionBeforePositionInRoot
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=335006:335027

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv947qlpvMIwUePSTdnUqD3YSWjdPoYhsUYMznxxC-K4Uf4jN3hOFJWJLrKAx8WfqrZpJ4QjxovaABVosl2MJze80OucLkX_YuDM_7Pb07ShwTPmowzhfcWPyeJSNJUI1zfnslUoySV6f0Y6t70zHfRfKeX1ThA?testcase_id=6733388528746496


Additional requirements: Requires Gestures

Issue manually filed by: kavvaru

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Components: Tools>Test>FindIt>CorrectResult
Labels: Findit-for-crash Te-Logged M-53
Owner: yosin@chromium.org
Status: Assigned (was: Untriaged)
Find it tool information
=================
Git blame below is NOT necessarily who introduced the crash nor the owner for it. Please check the code before assigning to anyone.(No CL in the regression range changed the crashing files.)

Author: mjs@apple.com
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/554c7634cddfec7925865257d362fa718c34ac3a
Time: Thu May 06 22:41:15 2010
The CL last changed line 716 of file Node.h, which is stack frame 0.

Author: commit-queue@webkit.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/a617e8a70e2f33152f9b00a7f6e86cd8ba8a29b5
Time: Sat Apr 21 00:18:20 2012
The CL last changed line 250 of file Node.h, which is stack frame 1.

Author: yosin
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/b3a7cd0489e05c4af2fc8cecd51b20b9818a348f
Time: Fri May 20 08:20:51 2016
The CL last changed line 458 of file Position.cpp, which is stack frame 2.

Author: yoichio
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/52032ceee8e754efb8100f977b92f8dbf1f6e30a
Time: Wed Oct 21 02:03:58 2015
The CL last changed line 604 of file EditingUtilities.cpp, which is stack frame 3.

Author: yosin@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/f51fc6c78f9de64180da4b464a95baae7ef1a58e
Time: Wed Aug 26 08:08:50 2015
The CL last changed line 627 of file EditingUtilities.cpp, which is stack frame 4.

Author: yoichio
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/52032ceee8e754efb8100f977b92f8dbf1f6e30a
Time: Wed Oct 21 02:03:58 2015
The CL last changed line 179 of file DeleteSelectionCommand.cpp, which is stack frame 5.

Author: yosin
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/32063af568e56a448b162dec06f9dfdaa6f08c61
Time: Tue Feb 16 02:24:31 2016
The CL last changed line 863 of file DeleteSelectionCommand.cpp, which is stack frame 6.

Suspected Project: chromium-blink
Suspected Component: Blink>DOM
=================

From the above information the changes made to the file "Position.cpp" from frame 2 is more related to it.
yosin @ Could you please look into this issue if it is related to your change,else please help us in finding the appropriate owner for this issue.

Thanks,
Project Member

Comment 2 by ClusterFuzz, Sep 27 2016

ClusterFuzz has detected this issue as fixed in range 419848:419971.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6733388528746496

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_lsan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000010
Crash State:
  blink::PositionTemplate<blink::EditingAlgorithm<blink::NodeTraversal> >::lastPos
  blink::PositionTemplate<blink::EditingAlgorithm<blink::NodeTraversal> > blink::l
  blink::lastEditablePositionBeforePositionInRoot
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=335006:335027
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=419848:419971

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv947qlpvMIwUePSTdnUqD3YSWjdPoYhsUYMznxxC-K4Uf4jN3hOFJWJLrKAx8WfqrZpJ4QjxovaABVosl2MJze80OucLkX_YuDM_7Pb07ShwTPmowzhfcWPyeJSNJUI1zfnslUoySV6f0Y6t70zHfRfKeX1ThA?testcase_id=6733388528746496


Additional requirements: Requires Gestures

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 3 by ClusterFuzz, Sep 27 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 4 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment