New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 818868 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Null-dereference READ in blink::ShapeResult::CreateForTabulationCharacters

Project Member Reported by ClusterFuzz, Mar 5 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5158552931663872

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Null-dereference READ
Crash Address: 0x000000000128
Crash State:
  blink::ShapeResult::CreateForTabulationCharacters
  blink::CachingWordShapeIterator::NextForAllowTabs
  TextWidth
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=523880:523906

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5158552931663872

Additional requirements: Requires HTTP

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Mar 5 2018

Components: Blink>Layout Platform
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Cc: brajkumar@chromium.org
Labels: M-65 Test-Predator-Wrong CF-NeedsTriage
Unable to find actual suspect through code search and also from the provided CL under regression range, hence adding appropriate label and requesting some one from layout team to look in to this issue.

Thanks!

Comment 3 by e...@chromium.org, Mar 6 2018

Status: WontFix (was: Untriaged)
Unable to reproduce and no relevant changes in regression range.
Project Member

Comment 4 by ClusterFuzz, Mar 13 2018

Labels: Needs-Feedback
ClusterFuzz testcase 5158552931663872 is still reproducing on tip-of-tree build (trunk).

If this testcase was not reproducible locally or unworkable, ignore this notification and we will file another bug soon with hopefully a better and workable testcase.

Otherwise, if this is not intended to be fixed (e.g. this is an intentional crash), please add ClusterFuzz-Ignore label to prevent future bug filing with similar crash stacktrace.

Sign in to add a comment