New issue
Advanced search Search tips

Issue 698574 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Mar 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Mac
Pri: 1
Type: Bug



Sign in to add a comment

!source->parentNode() in Document::adoptNode()

Project Member Reported by ClusterFuzz, Mar 5 2017

Issue description

Comment 1 Deleted

This looks to be fixed here  crbug.com/697737#c3 , ran Redo fix if its really fixed it.

Components: Blink>DOM

Comment 4 by tkent@chromium.org, Mar 10 2017

Status: Available (was: Untriaged)
Summary: !source->parentNode() in Document::adoptNode() (was: !source->parentNode() in Document.cpp)

Comment 5 by tkent@chromium.org, Mar 15 2017

Owner: tkent@chromium.org
Status: Started (was: Available)
Still reproducible with ToT.

Comment 7 by tkent@chromium.org, Mar 15 2017

Status: Fixed (was: Started)
Project Member

Comment 8 by ClusterFuzz, Mar 16 2017

Labels: OS-Mac OS-Android
Project Member

Comment 9 by ClusterFuzz, Mar 18 2017

ClusterFuzz has detected this issue as fixed in range 456626:457736.

Detailed report: https://clusterfuzz.com/testcase?key=4668640680214528

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_lsan_chrome_mp
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  !source->parentNode() in Document.cpp
  blink::Document::adoptNode
  blink::V8Document::adoptNodeMethodCallback
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_lsan_chrome_mp&range=454203:454233
Fixed: https://clusterfuzz.com/revisions?job=linux_lsan_chrome_mp&range=456626:457736

Reproducer Testcase: https://clusterfuzz.com/download/AMIfv97kzMjXhtXxi_F7vmQ3RYTprSMkxrT0LpdlK3HMjfyH1UYnfx6Q6PqsQGsPHFBim6K41ib0WybHGm5BeXW-zZ1IY2VsB8pGShg7wIUae2qTybv0SnlUoEUk7Vv3jCmETwtkvReJk9Xyv2j6T3onhX5IVL0HoDH0Av-sRgIXbk56T_xgD9iZVFAyRm9xLgWY8-7EEwKfeDfv5QE89t-Yg4_Ppqrlzymb-LzCdrp-3ITexbVLLbU1MUiI96CrOiegzhp9xoZZ6nJ7e3oHh967IDWDTiGZ4VOwPhakYDLB3YMALwiD-c4HASgJYIXuWTQs69x3Nb4wyR5RfC8nzX9bFvWOqknL5vhyhz9BcXx18TMDI1w5AsjC9tTTXwhJ3OrDA_d8s0t0iwhf2r1MlRt-wH5fvnCK6g?testcase_id=4668640680214528


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Sign in to add a comment