New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 686006 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Not working on Chrome any more
Closed: Feb 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

i < size() in Vector.h

Project Member Reported by ClusterFuzz, Jan 27 2017

Issue description

Comment 1 by tkent@chromium.org, Jan 27 2017

Components: Blink>CSS
Cc: bugsnash@chromium.org
Labels: Test-Predator-Wrong M-58
Owner: meade@chromium.org
Status: Assigned (was: Untriaged)
meade@: Could you please take a look into this if its related to your change.
Assigned referring to the  issue 681356 .Feel free to dupe it if its the same.
Currently its impacting to the head.
Project Member

Comment 3 by ClusterFuzz, Feb 1 2017

ClusterFuzz has detected this issue as fixed in range 447218:447232.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5793132894748672

Fuzzer: lcamtuf_cross_fuzz
Job Type: linux_tsan_chrome_mp
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  i < size() in Vector.h
  blink::TransformBuilder::createTransformOperations
  blink::StyleBuilderConverter::convertTransformOperations
  
Sanitizer: thread (TSAN)

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=445525:445713
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=447218:447232

Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv96d4w9P8yrifbqmkl4JcxX1Nbz59Rp84aY56-daUchxoE_K7GTcKZW0outxVXOz8jitJl29EwphhpbRceQEvW2_t4PNbFFaOq7SWd5M2Kwk3CFK-DcZlJDDwdMp2eNtRjLw4tKBg3ktPl6uwbtMBgJ5DnnqEPlJQheyP1w63i9jEgvO68gHHHdkLjwFgC00qMydMPTuNSf16O8ddK3eiYYyfsZ2DTBSssTTLCBgQV77VBjl8tXHM7HRLVw20LGz657YBSdc5jNLd8XCP2tizkjPX8H9a3M2cA4zjlIBY3eAWjzwnKAeLSVM-14PCPRDZDNrya7sjq4MujxJC2TrQTeG-6TUZKK_bKLq5zT41au2SrBnjIY?testcase_id=5793132894748672


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 4 by ClusterFuzz, Feb 1 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 5793132894748672 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment