New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 712978 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Last visit > 30 days ago
Closed: Apr 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug

Blocking:
issue 657748



Sign in to add a comment

Crash in blink::LayoutObject::getUncachedPseudoStyle

Project Member Reported by ClusterFuzz, Apr 19 2017

Issue description

Cc: msrchandra@chromium.org
Components: Blink>Layout
Labels: M-60 Test-Predator-Correct-CLs
Owner: eco...@igalia.com
Status: Assigned (was: Untriaged)
Assigning to the concern owner from Predator results --
The result is a list of CLs that change the crashed files. 

Author: ecobos
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/5fce73c8d68a52abbd31359c04373077c477e16c
Time: Wed Feb 22 10:07:11 2017
File LayoutObject.cpp is changed in this cl (and is part of stack frame #0, "content_shell!blink::LayoutObject::getUncachedPseudoStyle+0x17"; frame #1, "content_shell!blink::LayoutObject::getUncachedSelectionStyle+0x7b"; frame #2, "content_shell!blink::LayoutObject::selectionColor+0x29"; frame #3, "content_shell!blink::LayoutObject::selectionForegroundColor+0x13")
Minimum distance from crash line to modified line: 37. (file: LayoutObject.cpp, crashed on: 3093, modified: 3056).

@ecobos -- Could you please look into the issue, kindly re-assign if this is not related to your changes.
Thank You.

Comment 2 by eco...@igalia.com, Apr 19 2017

Blocking: 657748
Yeah, this one is mine. It's not super-urgent, because it uses display: contents, which is not shipped yet.

I still need to implement the "display: contents as a replaced element acts like display: none", which should fix this.

Thanks for the report!
Project Member

Comment 3 by ClusterFuzz, Apr 20 2017

ClusterFuzz has detected this issue as fixed in range 465765:465806.

Detailed report: https://clusterfuzz.com/testcase?key=5145750402236416

Fuzzer: mbarbella_js_mutation_layout
Job Type: windows_syzyasan_content_shell
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 0x0000000f
Crash State:
  blink::LayoutObject::getUncachedPseudoStyle
  blink::LayoutObject::getUncachedSelectionStyle
  blink::LayoutObject::selectionColor
  
Memory Tool: SYZYASAN

Regressed: https://clusterfuzz.com/revisions?job=windows_syzyasan_content_shell&range=451929:451968
Fixed: https://clusterfuzz.com/revisions?job=windows_syzyasan_content_shell&range=465765:465806

Reproducer Testcase: https://clusterfuzz.com/download/AMIfv95clHJMFKzy-TdwnKtWSPLU6yCYR4ObLxhT57S02lA8w9xPYQJzhPPjzen04iQBijUyVJyT444krUQ56KQMiTNvgaJWQW5xw2Za3CgZAst5FYdEyseIKiD5xVAU9OxqagwNPdoqxSPqAWpDZ4rBqqUNx93RL1FhqarPV5XmAxTP6CUDui6GxuKJBxnVf7z8WVt7cWRCCvRghSwvv0PN2CE8S4hVzU701MQugBZabr-kQGNe_VQEbiUiWiSWLH_lsSNear4o10jZ0r3Pv4r8xCbGIptlzBBMZz8VrI6wS0TonNRUHF1b8crv2Sj9OtS6UgfHKJnzcINUq4GktgkwDJ_yA_Zwmhm9zLM5b4SxVSxmhZ26Ei3CEecwqIPb0K78hl1J5jsPIMedQnfd3NvEk042DtszZg?testcase_id=5145750402236416


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 4 by ClusterFuzz, Apr 20 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 5145750402236416 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment