New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 742184 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Sep 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Stack-overflow in blink::CachingWordShapeIterator::ShapeWordWithoutSpacing

Project Member Reported by ClusterFuzz, Jul 13 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5799773289578496

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_asan_chrome_mp
Platform Id: linux

Crash Type: Stack-overflow
Crash Address: 0x7fff0e3e5ff8
Crash State:
  blink::CachingWordShapeIterator::ShapeWordWithoutSpacing
  blink::CachingWordShapeIterator::ShapeWord
  blink::CachingWordShapeIterator::ShapeToEndIndex
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_mp&range=133679:133688

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5799773289578496


Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Labels: Pri-2
Stack-overflow, Out of memory and Timeout issues are 'P2'.
Labels: Test-Predator-Wrong CF-NeedsTriage M-63
Redo Task has been performed for a better regression range.
Thank You.
Cc: msrchandra@chromium.org kkaluri@chromium.org
Components: Blink
Labels: -CF-NeedsTriage
Owner: bugsnash@chromium.org
Status: Assigned (was: Untriaged)
Predator and CL could not provide any possible suspects.
Using Code Search for the file, "CachingWordShapeIterator.cpp" assigning to the concern owner who might be related or worked on similar file.

Suspect CL: https://chromium.googlesource.com/chromium/src/+/2083513f84c5d1c914275031d0064875e27b28f8

bugsnash@ -- Could you please look into the issue, kindly re-assign if this is not related to your changes.


Thank You.
Components: -Blink Blink>Layout>Table
Is this possibly a recursive table layout?
Cc: e...@chromium.org
Components: -Blink>Layout>Table Blink>Layout
Owner: ----
Status: Untriaged (was: Assigned)
The test case exponentially increases the size of the dom. I don't know what's supposed to happen in that case.

+eae who might know
Labels: CF-NeedsTriage

Comment 7 by e...@chromium.org, Sep 22 2017

Status: WontFix (was: Untriaged)
Stack overflows due to deeply nested DOM is considered WontFix.

Sign in to add a comment