New issue
Advanced search Search tips

Issue 650884 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jan 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

m_selectionInFlatTree.isValidFor(document()). VisibleSelection(base: OBJECT clas

Project Member Reported by ClusterFuzz, Sep 27 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6612371709886464

Fuzzer: bj_broddelwerk
Job Type: linux_debug_chrome
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  m_selectionInFlatTree.isValidFor(document()). VisibleSelection(base: OBJECT clas
  blink::SelectionEditor::updateIfNeeded
  blink::FrameSelection::updateIfNeeded
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_chrome&range=398017:398731

Minimized Testcase (2.75 Kb): https://cluster-fuzz.appspot.com/download/AMIfv950UTFwZYh-dSkCgjNYaWUrohdk0YNCWwfgBSXf4055qTHxRuL5z-CVpPI9FIVu5j7zqT9i2oGN7w3W78RvObSxtHRTZDxZgNi4_rTAJGmYn2c5Dt0q4xZ8HUaknFKUxCeYxQJRRq-wIfu_VZSzUibAfWucwg?testcase_id=6612371709886464

Issue manually filed by: mummareddy

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Components: Blink>Editing Tools>Test>FindIt>NoResult
Labels: M-54 Te-Logged M-53
Owner: yosin@chromium.org
Status: Assigned (was: Untriaged)
Through code search on file SelectionEditor.cpp, suspected CL is 

https://chromium.googlesource.com/chromium/src/+/9c38a83b780e6cbd388579067b137ef12a39ff0c%5E%21/third_party/WebKit/Source/core/editing/SelectionEditor.cpp
yosin@, could you please take a look and help us to find correct owner if it is not related your changes.
Components: -Tools>Test>FindIt>NoResult
Project Member

Comment 3 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 4 by yosin@chromium.org, Nov 28 2016

Status: Available (was: Assigned)
Lower to Pri-2, since it is cause by unusual HTML, e.g. OPTGROUP in OBJECT.

SelectionInFlatTree.m_base is orphan node as below:


OPTGROUP
	#shadow-root
*		DIV id="optgroup-label" style="padding: 0px 2px 1px; min-height: 1.2em;"
		CONTENT
	#text "\n"

Comment 5 by yosin@chromium.org, Nov 28 2016

Labels: -Pri-1 Pri-2

Comment 6 by yosin@chromium.org, Dec 2 2016

Owner: ----
Project Member

Comment 7 by ClusterFuzz, Jan 1 2017

Status: WontFix (was: Available)
ClusterFuzz testcase 6612371709886464 is flaky and no longer reproduces, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment