NextSentencePosition() causes invalid range |
|||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5477796909678592 Fuzzer: ifratric-browserfuzzer-v3 Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: start <= end (OUTPUT id="htmlvarNUMBER" (editable)id="htmlvarNUMBER" (editable) blink::TextIteratorAlgorithm<>::TextIteratorAlgorithm blink::NextBoundary Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=475811:475824 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5477796909678592 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Apr 1 2018
Automatically adding ccs based on suspected regression changelists: Make TextIterator constructor to take only proper range by yosin@chromium.org - https://chromium.googlesource.com/chromium/src/+/984f4b2c4df57ae840917a1d79f95a54e68e2c7b Eliminate DocumentMarker and TextMatchMarker copy constructors by rlanday@chromium.org - https://chromium.googlesource.com/chromium/src/+/fa78f83615f6278ffe657bb6119d1b8339920b36 If this is incorrect, please let us know why and apply the Test-Predator-Wrong-CLs label.
,
Apr 2 2018
Lower to Pri-3 since real world usage of Selection#modify() with 'sentence' is low. |
|||
►
Sign in to add a comment |
|||
Comment 1 by ClusterFuzz
, Apr 1 2018Labels: Test-Predator-Auto-Components