FrameSelection::selectAll() should work only for attached document |
|||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5338142749229056 Fuzzer: ifratric-browserfuzzer-v3 Job Type: linux_asan_chrome_media Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x0000000005b0 Crash State: blink::Document::updateStyleAndLayoutTreeIgnorePendingStylesheets blink::Document::updateStyleAndLayoutIgnorePendingStylesheets blink::FrameSelection::setSelection Sanitizer: address (ASAN) Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=450347:450401 Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv964HeXM0kVzEy0j4jGl67LbK3ZqZLMDE9xUn0oQ_Jv0tK0pZ-0ae2Rwy1RohNNesHyoTD8gl8OZtp9e7fzBUZSTjPQkmdw5z0OMmwubBDpsW7TcNGwvYkuAY4bg4i5Ix_W4BPF-NMROW-L2kB3nKrtGaJmIF-Ca4YaTzqXj96JPYn0h43NGg04PyyI9Q1XObymX4wJanhHIRSycydvOE26wMRmUmFD3d_Lp2HI71Ei_cZ_FsiqE1jmsjr2bYgqG4-THZO0ABFpALLJFejVoHAMp1ORRaUuL2vxl7HyQ0gdwcgEhoPKPjwXbWgxS6z09XxKGmqRh-d57JC3BVEWggkTkd_eUtE60X8vwhN8vxvzohoqu5bz0OuOXxm8o7mgJpBhvGcMH3ASuv6TvXRl7WQ3u70zB_Q?testcase_id=5338142749229056 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Feb 20 2017
Lower to Pri-2, since the script attempt to execute "selectAll" command for detached IFRAME.
,
Mar 9 2017
ClusterFuzz has detected this issue as fixed in range 455091:455392. Detailed report: https://clusterfuzz.com/testcase?key=5338142749229056 Fuzzer: ifratric-browserfuzzer-v3 Job Type: linux_asan_chrome_media Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x0000000005b0 Crash State: blink::Document::updateStyleAndLayoutTreeIgnorePendingStylesheets blink::Document::updateStyleAndLayoutIgnorePendingStylesheets blink::FrameSelection::setSelection Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_media&range=450347:450401 Fixed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_media&range=455091:455392 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv964HeXM0kVzEy0j4jGl67LbK3ZqZLMDE9xUn0oQ_Jv0tK0pZ-0ae2Rwy1RohNNesHyoTD8gl8OZtp9e7fzBUZSTjPQkmdw5z0OMmwubBDpsW7TcNGwvYkuAY4bg4i5Ix_W4BPF-NMROW-L2kB3nKrtGaJmIF-Ca4YaTzqXj96JPYn0h43NGg04PyyI9Q1XObymX4wJanhHIRSycydvOE26wMRmUmFD3d_Lp2HI71Ei_cZ_FsiqE1jmsjr2bYgqG4-THZO0ABFpALLJFejVoHAMp1ORRaUuL2vxl7HyQ0gdwcgEhoPKPjwXbWgxS6z09XxKGmqRh-d57JC3BVEWggkTkd_eUtE60X8vwhN8vxvzohoqu5bz0OuOXxm8o7mgJpBhvGcMH3ASuv6TvXRl7WQ3u70zB_Q?testcase_id=5338142749229056 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Mar 9 2017
ClusterFuzz testcase 5338142749229056 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
|||
►
Sign in to add a comment |
|||
Comment 1 by nyerramilli@chromium.org
, Feb 15 2017Components: Blink>Editing
Labels: Test-Predator-Correct-CLs M-58
Owner: yosin@chromium.org
Status: Assigned (was: Untriaged)