JustifyRight command crashes with BUTTON and VIDEO |
|||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6053422156742656 Fuzzer: ifratric-browserfuzzer-v3 Job Type: mac_asan_chrome Platform Id: mac Crash Type: CHECK failure Crash Address: Crash State: startPosition.compareTo(endPosition) <= 0 in Serialization.cpp blink::CreateMarkupAlgorithm<blink::EditingAlgorithm<blink::NodeTraversal> >::cr blink::createMarkup Sanitizer: address (ASAN) Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=454203:454233 Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv94wdD-gxklqpD5gwcF2mFEkh7gC1UFn07UK4Yrf_qvoTsYWYIj7nlp9NlTW9oyzm8Lt5pVEJQKpzquEhfECSCUBuBhCeATtmO9OJ0e4GeG56pu59tmrvRT7Soy2QnHiO7lkpTgZe6tTnXOff9i-ewtiejyU4H7617l1DorLmpYd-ilsak9ojA6JdmEUn2s3ZqPP9kRhfNfnQ575IcvUuqNq68SUzoDauG3lTPsaOBwb3DTiwjz4zdqo405mK0j3eoOeUkC9PQ3yNov-Llh9Qjaqen7FrhGe0osrWzPYm088snbGcWdWwWM7wQ1TCyrI1xQPzdzXNpc0287_A0ulgF3XAA8BssBTsEB2TtUg4ZGLzlqqjls?testcase_id=6053422156742656 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Mar 5 2017
My CL didn't change any behavior. Route to Editing triage.
,
Mar 6 2017
Lower to Pri-2 since real world usage of "JustifyRight" command is low. BODY E BUTTON id="htmlvar00002" (editable) (focused) DIV (editable) BR (editable) S #text "JnrM~I2geGN\\` L*A>" #text "\n" VIDEO #shadow-root DIV DIV INPUT style="display: none;" #shadow-root #text "" DIV DIV style="display: none;" INPUT style="display: none;" #shadow-root #text "" DIV style="display: none;" #text "0:00" DIV style="display: none;" #text "/ 0:00" INPUT style="display: none;" #shadow-root DIV style="-webkit-appearance:inherit" DIV id="track" DIV id="thumb" INPUT style="display: none;" #shadow-root #text "" INPUT style="display: none;" #shadow-root DIV style="-webkit-appearance:inherit" DIV id="track" DIV id="thumb" INPUT style="display: none;" #shadow-root #text "" INPUT style="display: none;" #shadow-root #text "" INPUT style="display: none;" #shadow-root #text "" INPUT style="display: none;" #shadow-root #text "" INPUT style="display: none;" #shadow-root #text "" DIV style="display: none;" DIV style="display: none;" LABEL INPUT style="display: none;" #shadow-root #text "" #text "Play" LABEL INPUT style="display: none;" #shadow-root #text "" #text "Fullscreen" LABEL INPUT style="display: none;" #shadow-root #text "" #text "Download" LABEL INPUT style="display: none;" #shadow-root #text "" #text "Mute" LABEL INPUT style="display: none;" #shadow-root #text "" #text "Cast" LABEL INPUT style="display: none;" #shadow-root #text "" #text "Captions" #text "\n" SOURCE
,
Mar 16 2017
,
May 22 2017
Bulk set to Pri-3 for cluster fuzz bugs. Since these issues are happens with unusual HTML.
,
Sep 23 2017
,
Oct 21 2017
ClusterFuzz has detected this issue as fixed in range 510370:510391. Detailed report: https://clusterfuzz.com/testcase?key=6053422156742656 Fuzzer: ifratric-browserfuzzer-v3 Job Type: mac_asan_chrome Platform Id: mac Crash Type: CHECK failure Crash Address: Crash State: start_position.CompareTo(end_position) <= 0 in Serialization.cpp blink::CreateMarkupAlgorithm<blink::EditingAlgorithm<blink::NodeTraversal> >::Cr blink::CreateMarkup Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=454203:454233 Fixed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=510370:510391 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6053422156742656 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Oct 21 2017
ClusterFuzz testcase 6053422156742656 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
|||||||
►
Sign in to add a comment |
|||||||
Comment 1 by msrchandra@chromium.org
, Mar 3 2017Labels: Test-Predator-Wrong M-58
Owner: tkent@chromium.org
Status: Assigned (was: Untriaged)