New issue
Advanced search Search tips

Issue 713425 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 712803
Owner: ----
Closed: Apr 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug



Sign in to add a comment

Crash in blink::PaintInvalidator::MapLocalRectToVisualRectInBacking<blink::LayoutRect,bli

Project Member Reported by ClusterFuzz, Apr 19 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=6241231891070976

Fuzzer: ifratric-browserfuzzer-v3
Job Type: windows_asan_chrome
Platform Id: windows

Crash Type: UNKNOWN READ
Crash Address: 0x00000000
Crash State:
  blink::PaintInvalidator::MapLocalRectToVisualRectInBacking<blink::LayoutRect,bli
  blink::PaintInvalidatorContext::MapLocalRectToVisualRectInBacking
  blink::ScrollControlVisualRect
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=windows_asan_chrome&range=464127:464504

Reproducer Testcase: https://clusterfuzz.com/download/AMIfv97dzBzO0ChRkcOSXut5FiSkQbvsrfsGUYxj-M_ICF_Qf4NatRhA6XMk16LDKWDdRS1VflgVWWWCGaUeQ8T0YvImXN10IOgfEC0Cd9G3QQLb6HmjdpLKHlueYM-CdNQxkywJ000GwfQpDjErdtIjSnnn38O-CIdxdE7auUG3nBA-kmNRy9KgUKdgYwenaERrbApSWi3KApjYW-MksrBYoDrRRgU8BDQKoh3nKdv__PMM8BHIThs2JgdFCY-MJ29Ih9pXcz1-k_st1T7J3_XnVuRPuCkA59X2BxOUCoyz4W41QDxB40uIwIG4EdJhcVnZYiEXaZFfkW-xfIbbVDVNV99VzY3FZUJ7EHGSdh0uLT1HlZaLgh0?testcase_id=6241231891070976


Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: wangxianzhu@chromium.org
Components: Blink>Paint
Labels: M-60 Test-Predator-Wrong
Mergedinto: 712803
Status: Duplicate (was: Untriaged)
Looks like dupe of  issue 712803 . 
Project Member

Comment 2 by ClusterFuzz, Apr 19 2017

ClusterFuzz has detected this issue as fixed in range 465377:465420.

Detailed report: https://clusterfuzz.com/testcase?key=6241231891070976

Fuzzer: ifratric-browserfuzzer-v3
Job Type: windows_asan_chrome
Platform Id: windows

Crash Type: UNKNOWN READ
Crash Address: 0x00000000
Crash State:
  blink::PaintInvalidator::MapLocalRectToVisualRectInBacking<blink::LayoutRect,bli
  blink::PaintInvalidatorContext::MapLocalRectToVisualRectInBacking
  blink::ScrollControlVisualRect
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=windows_asan_chrome&range=464127:464504
Fixed: https://clusterfuzz.com/revisions?job=windows_asan_chrome&range=465377:465420

Reproducer Testcase: https://clusterfuzz.com/download/AMIfv97dzBzO0ChRkcOSXut5FiSkQbvsrfsGUYxj-M_ICF_Qf4NatRhA6XMk16LDKWDdRS1VflgVWWWCGaUeQ8T0YvImXN10IOgfEC0Cd9G3QQLb6HmjdpLKHlueYM-CdNQxkywJ000GwfQpDjErdtIjSnnn38O-CIdxdE7auUG3nBA-kmNRy9KgUKdgYwenaERrbApSWi3KApjYW-MksrBYoDrRRgU8BDQKoh3nKdv__PMM8BHIThs2JgdFCY-MJ29Ih9pXcz1-k_st1T7J3_XnVuRPuCkA59X2BxOUCoyz4W41QDxB40uIwIG4EdJhcVnZYiEXaZFfkW-xfIbbVDVNV99VzY3FZUJ7EHGSdh0uLT1HlZaLgh0?testcase_id=6241231891070976


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Sign in to add a comment