Crash in blink::LayoutObject::getUncachedPseudoStyle |
|||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5145750402236416 Fuzzer: mbarbella_js_mutation_layout Job Type: windows_syzyasan_content_shell Platform Id: windows Crash Type: UNKNOWN Crash Address: 0x0000000f Crash State: blink::LayoutObject::getUncachedPseudoStyle blink::LayoutObject::getUncachedSelectionStyle blink::LayoutObject::selectionColor Memory Tool: SYZYASAN Regressed: https://clusterfuzz.com/revisions?job=windows_syzyasan_content_shell&range=451929:451968 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv95clHJMFKzy-TdwnKtWSPLU6yCYR4ObLxhT57S02lA8w9xPYQJzhPPjzen04iQBijUyVJyT444krUQ56KQMiTNvgaJWQW5xw2Za3CgZAst5FYdEyseIKiD5xVAU9OxqagwNPdoqxSPqAWpDZ4rBqqUNx93RL1FhqarPV5XmAxTP6CUDui6GxuKJBxnVf7z8WVt7cWRCCvRghSwvv0PN2CE8S4hVzU701MQugBZabr-kQGNe_VQEbiUiWiSWLH_lsSNear4o10jZ0r3Pv4r8xCbGIptlzBBMZz8VrI6wS0TonNRUHF1b8crv2Sj9OtS6UgfHKJnzcINUq4GktgkwDJ_yA_Zwmhm9zLM5b4SxVSxmhZ26Ei3CEecwqIPb0K78hl1J5jsPIMedQnfd3NvEk042DtszZg?testcase_id=5145750402236416 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 19 2017
Yeah, this one is mine. It's not super-urgent, because it uses display: contents, which is not shipped yet. I still need to implement the "display: contents as a replaced element acts like display: none", which should fix this. Thanks for the report!
,
Apr 20 2017
ClusterFuzz has detected this issue as fixed in range 465765:465806. Detailed report: https://clusterfuzz.com/testcase?key=5145750402236416 Fuzzer: mbarbella_js_mutation_layout Job Type: windows_syzyasan_content_shell Platform Id: windows Crash Type: UNKNOWN Crash Address: 0x0000000f Crash State: blink::LayoutObject::getUncachedPseudoStyle blink::LayoutObject::getUncachedSelectionStyle blink::LayoutObject::selectionColor Memory Tool: SYZYASAN Regressed: https://clusterfuzz.com/revisions?job=windows_syzyasan_content_shell&range=451929:451968 Fixed: https://clusterfuzz.com/revisions?job=windows_syzyasan_content_shell&range=465765:465806 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv95clHJMFKzy-TdwnKtWSPLU6yCYR4ObLxhT57S02lA8w9xPYQJzhPPjzen04iQBijUyVJyT444krUQ56KQMiTNvgaJWQW5xw2Za3CgZAst5FYdEyseIKiD5xVAU9OxqagwNPdoqxSPqAWpDZ4rBqqUNx93RL1FhqarPV5XmAxTP6CUDui6GxuKJBxnVf7z8WVt7cWRCCvRghSwvv0PN2CE8S4hVzU701MQugBZabr-kQGNe_VQEbiUiWiSWLH_lsSNear4o10jZ0r3Pv4r8xCbGIptlzBBMZz8VrI6wS0TonNRUHF1b8crv2Sj9OtS6UgfHKJnzcINUq4GktgkwDJ_yA_Zwmhm9zLM5b4SxVSxmhZ26Ei3CEecwqIPb0K78hl1J5jsPIMedQnfd3NvEk042DtszZg?testcase_id=5145750402236416 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Apr 20 2017
ClusterFuzz testcase 5145750402236416 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
|||
►
Sign in to add a comment |
|||
Comment 1 by msrchandra@chromium.org
, Apr 19 2017Components: Blink>Layout
Labels: M-60 Test-Predator-Correct-CLs
Owner: eco...@igalia.com
Status: Assigned (was: Untriaged)