New issue
Advanced search Search tips

Issue 779054 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 777253
Owner:
Closed: Oct 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Windows , Mac
Pri: 1
Type: Bug



Sign in to add a comment

Null-dereference READ in blink::VisualOffsetFromPaintOffsetRoot

Project Member Reported by ClusterFuzz, Oct 27 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=4582011493941248

Fuzzer: inferno_twister_c
Job Type: linux_asan_chrome_media
Platform Id: linux

Crash Type: Null-dereference READ
Crash Address: 0x0000000000a0
Crash State:
  blink::VisualOffsetFromPaintOffsetRoot
  blink::PaintPropertyTreeBuilder::UpdatePropertiesForSelf
  blink::PrePaintTreeWalk::Walk
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_media&range=511462:511489

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4582011493941248

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Oct 27 2017

Labels: OS-Windows OS-Android OS-Mac
Project Member

Comment 2 by ClusterFuzz, Oct 27 2017

Labels: ClusterFuzz-Top-Crash ReleaseBlock-Beta M-63
Testcase 4582011493941248 is a top crash on ClusterFuzz for linux, mac and windows platforms. Please prioritize fixing this crash.

Marking this crash as a Beta release blocker.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Components: Blink>Paint
Owner: wangxianzhu@chromium.org
Status: Assigned (was: Untriaged)
Labels: -ReleaseBlock-Beta ReleaseBlock-Stable
Cc: wangxianzhu@chromium.org
Labels: -M-63 M-64 ClusterFuzz-Wrong
Owner: chrishtr@chromium.org
Based on the crash stack, this seems to be caused by https://chromium-review.googlesource.com/719765 (in the regression range) which seems not in M-63 (Clusterfuzz-Wrong for this).

chrishtr@ can you take a look?
Mergedinto: 777253
Status: Duplicate (was: Assigned)
Project Member

Comment 8 by ClusterFuzz, Oct 28 2017

ClusterFuzz has detected this issue as fixed in range 512010:512075.

Detailed report: https://clusterfuzz.com/testcase?key=4582011493941248

Fuzzer: inferno_twister_c
Job Type: linux_asan_chrome_media
Platform Id: linux

Crash Type: Null-dereference READ
Crash Address: 0x0000000000a0
Crash State:
  blink::VisualOffsetFromPaintOffsetRoot
  blink::PaintPropertyTreeBuilder::UpdatePropertiesForSelf
  blink::PrePaintTreeWalk::Walk
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_media&range=511462:511489
Fixed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_media&range=512010:512075

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4582011493941248

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Sign in to add a comment