Float-cast-overflow in gfx::Transform::IsIdentityOrIntegerTranslation |
||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5652813230374912 Fuzzer: ifratric-browserfuzzer-v3 Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Float-cast-overflow Crash Address: Crash State: gfx::Transform::IsIdentityOrIntegerTranslation cc::TransformTree::UpdateNodeAndAncestorsHaveIntegerTranslations cc::TransformTree::UpdateTransforms Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=435261:438085 Minimized Testcase (0.10 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97lQx1Qw3uwfZIhYWRLPuqIsshdXooelzmdcxy8gj2kYEVOUBThXuEBnbar8ldnOlorTG2DOuFBMogETTgNRe2L8uQ4Xezcfj38Jg6AKhbdtnsxlv_1anYWHlTUTFwCpuMeP50EKxJRM4AhkIabhWKTHVs4Fw?testcase_id=5652813230374912 <style> ol, label { flex-shrink: float; transform: translate3d(1px, 1px, 2147483647px);</style> <ol> Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Dec 20 2016
ClusterFuzz testcase 5652813230374912 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||
►
Sign in to add a comment |
||
Comment 1 by ClusterFuzz
, Dec 20 2016