New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 727325 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Not working on Chrome any more
Closed: Jun 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 1
Type: Bug-Regression



Sign in to add a comment

Stack-overflow in blink::SelectorFilterParentScope::PushParentIfNeeded

Project Member Reported by ClusterFuzz, May 29 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=4510361670909952

Fuzzer: bj_broddelwerk
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: Stack-overflow
Crash Address: 0x7fff596ccff8
Crash State:
  blink::SelectorFilterParentScope::PushParentIfNeeded
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=471987:472016

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4510361670909952


Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Components: Blink
Components: -Blink Blink>CSS
Owner: meade@chromium.org
Status: Assigned (was: Untriaged)
Labels: -Pri-1 Pri-2
Labels: -Type-Bug -Pri-2 ReleaseBlock-Stable Regressed-60 Pri-1 Type-Bug-Regression
Project Member

Comment 6 by sheriffbot@chromium.org, Jun 6 2017

Cc: bugsnash@chromium.org
This issue is marked as a release blocker with no milestone associated. Please add an appropriate milestone.

All release blocking issues should have milestones associated to it, so that the issue can tracked and the fixes can be pushed promptly.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: Update-Weekly
Labels: M-60
Cc: -bugsnash@chromium.org
Blockedon: 706281
Owner: ----
Status: Available (was: Assigned)
Owner: meade@chromium.org
Blockedon: -706281
meade@ - Could you please provide any update on this issue as it has been marked as a stable blocker.

Thanks...!!

Comment 14 by meade@chromium.org, Jun 22 2017

Cc: dstockwell@chromium.org infe...@chromium.org
I don't think we can do much about stack overflows... ccing dstockwell and inferno for further comment
Project Member

Comment 15 by ClusterFuzz, Jun 24 2017

ClusterFuzz has detected this issue as fixed in range 481851:481863.

Detailed report: https://clusterfuzz.com/testcase?key=4510361670909952

Fuzzer: bj_broddelwerk
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: Stack-overflow
Crash Address: 0x7fff596ccff8
Crash State:
  blink::SelectorFilterParentScope::PushParentIfNeeded
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=471987:472016
Fixed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=481851:481863

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4510361670909952


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 16 by ClusterFuzz, Jun 24 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Available)
ClusterFuzz testcase 4510361670909952 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Labels: Merge-TBD
[Auto-generated comment by a script] We noticed that this issue is targeted for M-60; it appears the fix may have landed after branch point, meaning a merge might be required. Please confirm if a merge is required here - if so add Merge-Request-60 label, otherwise remove Merge-TBD label. Thanks.
Labels: -Merge-TBD
There doesn't seem like there was any fix for this. Removing Merge-TBD label. 

Sign in to add a comment