CHECK failure: start <= end (#text "4-NUMBER"@offsetInAnchor[1] vs. #text "4-NUMBER"@offsetInAn |
||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5664930710945792 Fuzzer: mbarbella_js_mutation_layout Job Type: linux_ubsan_vptr_content_shell_drt Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: start <= end (#text "4-NUMBER"@offsetInAnchor[1] vs. #text "4-NUMBER"@offsetInAn blink::TextIteratorAlgorithm<>::TextIteratorAlgorithm blink::DocumentMarkerController::AddMarkerInternal Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_content_shell_drt&range=478364:478645 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5664930710945792 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Apr 2 2018
The CL is just a rename. Let's go through Blink>Layout triage process.
,
Apr 2 2018
Out-of-bound indexes are passed to blink::WebInputMethodControllerImpl::SetComposition().
,
Apr 6 2018
I put up a CL for fixing this: https://chromium-review.googlesource.com/c/chromium/src/+/993698 but xiaochengh@, yosin@, and I were unable to agree upon if this is the correct fix or not
,
Apr 6 2018
,
Apr 8 2018
ClusterFuzz has detected this issue as fixed in range 549059:549062. Detailed report: https://clusterfuzz.com/testcase?key=5664930710945792 Fuzzer: mbarbella_js_mutation_layout Job Type: linux_ubsan_vptr_content_shell_drt Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: start <= end (#text "4-NUMBER"@offsetInAnchor[1] vs. #text "4-NUMBER"@offsetInAn blink::TextIteratorAlgorithm<>::TextIteratorAlgorithm blink::DocumentMarkerController::AddMarkerInternal Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_content_shell_drt&range=478364:478645 Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_content_shell_drt&range=549059:549062 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5664930710945792 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Apr 8 2018
ClusterFuzz testcase 5664930710945792 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||||||
►
Sign in to add a comment |
||||||
Comment 1 by brajkumar@chromium.org
, Apr 2 2018Components: Blink>Layout
Labels: M-66 Test-Predator-Wrong
Owner: wangxianzhu@chromium.org
Status: Assigned (was: Untriaged)