New issue
Advanced search Search tips

Issue 677601 link

Starred by 1 user

Issue metadata

Status: Verified
Owner: ----
Closed: Apr 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug



Sign in to add a comment

Crash in blink::Node::isDescendantOf

Project Member Reported by ClusterFuzz, Dec 30 2016

Issue description

Comment 1 by sigbjo...@opera.com, Jan 11 2017

Components: Blink>Editing>Command
Labels: -Pri-1 Pri-2
Status: Available (was: Untriaged)
Project Member

Comment 3 by ClusterFuzz, Apr 19 2017

ClusterFuzz has detected this issue as fixed in range 449265:449274.

Detailed report: https://clusterfuzz.com/testcase?key=4661338938015744

Fuzzer: bj_broddelwerk
Job Type: windows_syzyasan_chrome
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 0x0000000b
Crash State:
  blink::Node::isDescendantOf
  blink::CompositeEditCommand::cloneParagraphUnderNewElement
  blink::CompositeEditCommand::moveParagraphWithClones
  
Memory Tool: SYZYASAN

Regressed: https://clusterfuzz.com/revisions?job=windows_syzyasan_chrome&range=440977:440981
Fixed: https://clusterfuzz.com/revisions?job=windows_syzyasan_chrome&range=449265:449274

Reproducer Testcase: https://clusterfuzz.com/download/AMIfv97DFovp1vznGYwEeSUZdrHjU50g2AgQr0DL9zxYyXY1dK6W4gF-6vDFXnFVbYgBWwQSquB2zFVQ8-wRihCPtCuwjAzmIhlsivgETb87Vb0Ro2kwne4hWbWLLBt2CJB2Llr6GEbJapKwLIJIeG3y2eEPUcbC5929BZiK_4aBLhtgmG4Ex50A4mJZw9OSKcjXaxLkw0IFf2SOWgp5aIGc4HlxzUPxyN9yLKpdSPiznIBk-f_YSLqBvEB1q0iYb2axKPvkmF0yhgSDWf8_b5-0MtRFANTra_rcXwFg10urwIqfigMcd8G2cUkt5Kil1n7UlZ9-UltkCrZrxGLDi2RADOpQQnsfS3qsnRx44Ac6_JxcdBzwlIQ?testcase_id=4661338938015744


Additional requirements: Requires Gestures

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 4 by ClusterFuzz, Apr 20 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Available)
ClusterFuzz testcase 4661338938015744 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment