Issue metadata
Sign in to add a comment
|
Null-dereference READ in blink::Element::SetIntegralAttribute |
||||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5754367109234688 Fuzzer: inferno_twister Job Type: linux_ubsan_vptr_chrome Platform Id: linux Crash Type: Null-dereference READ Crash Address: 0x000000000000 Crash State: blink::Element::SetIntegralAttribute blink::Document::WillChangeFrameOwnerProperties blink::HTMLFrameElementBase::SetMarginWidth Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=508795:508862 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5754367109234688 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Nov 3 2017
Automatically assigning owner based on suspected regression changelist https://chromium.googlesource.com/chromium/src/+/145660d6a05041e0da6a412598a29741b9efe816 (Invalid viewport meta width/height value should fall back to auto.). If this is incorrect, please remove the owner and apply the Test-Predator-Wrong-CLs label.
,
Nov 3 2017
I can still reproduce the crash with my patch's revert patch. https://chromium-review.googlesource.com/c/chromium/src/+/753802
,
Nov 3 2017
yosin@, could you take a look?
,
Nov 7 2017
,
Nov 7 2017
,
Nov 7 2017
,
Nov 7 2017
,
Nov 14 2017
Lower to Pri-3 since it is caused by unusual HTML and DOM mutation events.
,
Dec 27 2017
,
Jan 20 2018
ClusterFuzz has detected this issue as fixed in range 530461:530464. Detailed report: https://clusterfuzz.com/testcase?key=5754367109234688 Fuzzer: inferno_twister Job Type: linux_ubsan_vptr_chrome Platform Id: linux Crash Type: Null-dereference READ Crash Address: 0x000000000000 Crash State: blink::Element::SetIntegralAttribute blink::Document::WillChangeFrameOwnerProperties blink::HTMLFrameElementBase::SetMarginWidth Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=508795:508862 Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=530461:530464 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5754367109234688 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jan 20 2018
ClusterFuzz testcase 5754367109234688 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Jan 22 2018
@fergal FYI Probably your CL fixed this as well. https://chromium.googlesource.com/chromium/src/+/7d8f1e30e8d6918f4da3657e03be88d555deccd8
,
Jan 22 2018
|
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by ClusterFuzz
, Nov 3 2017Labels: Test-Predator-AutoComponents