Null-dereference in blink::Element::SynchronizeAttribute |
||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=6253764247027712 Fuzzer: inferno_twister Job Type: windows_syzyasan_chrome Platform Id: windows Crash Type: Null-dereference Crash Address: 0x0000002f Crash State: blink::Element::SynchronizeAttribute blink::Element::setAttribute blink::Element::SetIntegralAttribute Memory Tool: SYZYASAN Regressed: https://clusterfuzz.com/revisions?job=windows_syzyasan_chrome&range=434043:434111 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6253764247027712 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Sep 18 2017
Issue 765875 has been merged into this issue.
,
Sep 18 2017
,
Sep 18 2017
,
Sep 19 2017
,
Sep 21 2017
,
Sep 21 2017
kochi@, could you triage this?
,
Sep 21 2017
,
Sep 25 2017
Reproducing for me. Starting to look at it.
,
Sep 27 2017
The crash is happening with an combination of DOM mutation events, which is called during actual mutation is complete. Let me work on the fix.
,
Oct 1 2017
Automatically applying components based on information from OWNERS files. If this seems incorrect, please apply the Test-Predator-Wrong-Components label.
,
Oct 1 2017
,
Oct 23 2017
Rakina, could you take a look?
,
Oct 26 2017
ClusterFuzz testcase 6175370893328384 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Nov 3 2017
ClusterFuzz testcase 6253764247027712 is still reproducing on tip-of-tree build (trunk). Please re-test your fix against this testcase and if the fix was incorrect or incomplete, please re-open the bug. Otherwise, ignore this notification and add ClusterFuzz-Wrong label.
,
Dec 22 2017
Note to myself: here's my manually minimized test case. run with content_shell -run-layout-test. |
||||||||||||||
►
Sign in to add a comment |
||||||||||||||
Comment 1 by pnangunoori@chromium.org
, Sep 18 2017