Crash in blink::LinkStyle::setCSSStyleSheet |
||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5742867844956160 Fuzzer: inferno_webbot Job Type: windows_syzyasan_chrome Platform Id: windows Crash Type: UNKNOWN Crash Address: 0x00000007 Crash State: blink::LinkStyle::setCSSStyleSheet blink::CSSStyleSheetResource::checkNotify blink::Resource::finish Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_chrome&range=424963:424978 Minimized Testcase (0.06 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97NJdwvG2pHtIZ0QjS4Wc6Y8z0QKjfxqlxLPirn7B1eYlMJoWqLo_MHMk4I6q08jiM9S1u7cQB-LkRRGFWAGUquTqbyXAoGh2EcgkISzo4iOh4CA9cBexonUOBslyFAehYBZnWiBmwalJfoNLZmQbb3yH09Ow?testcase_id=5742867844956160 <script> window.location = "http://alabamaoutdoors.com";</script> Issue manually filed by: mummareddy See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Oct 14 2016
,
Oct 17 2016
Issue 655812 has been merged into this issue.
,
Oct 17 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/3b89d127027ca441b6abfcde56aee65add6423ca commit 3b89d127027ca441b6abfcde56aee65add6423ca Author: kouhei <kouhei@chromium.org> Date: Mon Oct 17 02:41:50 2016 Fix LinkStyle SRI check when against 0 sized resource. Before this CL, SRI check in LinkStyle::setCSSStyleSheet assumed that the target CSS resource had >0 size. However, it is possible that the CSS size is 0. This CL removes the assert that assumed resourceBuffer() != nullptr, which isn't true when the CSS empty. In addition, this CL also ensures SRI check on empty CSS resource, which doesn't affect user visible behaviour, but needed to emit SRI verification failure messages. Test by csharrison@chromium.org BUG= 655807 Review-Url: https://codereview.chromium.org/2418083002 Cr-Commit-Position: refs/heads/master@{#425611} [add] https://crrev.com/3b89d127027ca441b6abfcde56aee65add6423ca/third_party/WebKit/LayoutTests/fast/loader/sri-with-empty-response.html [add] https://crrev.com/3b89d127027ca441b6abfcde56aee65add6423ca/third_party/WebKit/LayoutTests/resources/empty.css [modify] https://crrev.com/3b89d127027ca441b6abfcde56aee65add6423ca/third_party/WebKit/Source/core/html/HTMLLinkElement.cpp
,
Oct 18 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Oct 18 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||||
►
Sign in to add a comment |
||||||
Comment 1 by mummare...@chromium.org
, Oct 13 2016Labels: M-56 Te-Logged
Owner: kouhei@chromium.org
Status: Assigned (was: Untriaged)