New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 828040 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 831634
Owner:
Last visit > 30 days ago
Closed: Apr 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Regression

Blocking:
issue 771643



Sign in to add a comment

Null-dereference READ in blink::LowestCommonAncestor<class blink::ClipPaintPropertyNode>

Project Member Reported by ClusterFuzz, Apr 2 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5366889069674496

Fuzzer: ifratric-browserfuzzer-v3
Job Type: windows_asan_chrome_no_sandbox
Platform Id: windows

Crash Type: Null-dereference READ
Crash Address: 0x000000000008
Crash State:
  blink::LowestCommonAncestor<class blink::ClipPaintPropertyNode>
  blink::ConversionContext::SwitchToClip
  blink::GraphicsLayer::PaintContents
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=windows_asan_chrome_no_sandbox&range=547394:547395

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5366889069674496

Additional requirements: Requires Gestures

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Cc: brajkumar@chromium.org
Components: Blink>Paint
Labels: -Type-Bug M-67 Test-Predator-Wrong Type-Bug-Regression
Owner: wangxianzhu@chromium.org
Status: Assigned (was: Untriaged)
Predator and CL could not provide any possible suspects.

Using Code Search for the file, "PaintPropertyNode.h" suspecting the below Cl might have caused this issue

Suspect CL: https://chromium.googlesource.com/chromium/src/+/1ce8d72d66f3dfce63347f20b1fae45c91c65a4c%5E%21/third_party/WebKit/Source/platform/graphics/paint/PaintPropertyNode.h

wangxianzhu@ -- Could you please check whether this is caused with respect to your change, if not please help us in assigning it to the right owner.

Thanks!
Blocking: 771643
Labels: -Pri-1 Pri-2
Owner: trchen@chromium.org
Lowering priority because the test case is too big and can't stably reproduce the issue.
Mergedinto: 831634
Status: Duplicate (was: Assigned)
 bug 831634  has a better test case.
Project Member

Comment 4 by ClusterFuzz, May 2 2018

ClusterFuzz has detected this issue as fixed in range 555311:555312.

Detailed report: https://clusterfuzz.com/testcase?key=5366889069674496

Fuzzer: ifratric-browserfuzzer-v3
Job Type: windows_asan_chrome_no_sandbox
Platform Id: windows

Crash Type: Null-dereference READ
Crash Address: 0x000000000008
Crash State:
  blink::LowestCommonAncestor<class blink::ClipPaintPropertyNode>
  blink::ConversionContext::SwitchToClip
  blink::GraphicsLayer::PaintContents
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=windows_asan_chrome_no_sandbox&range=547394:547395
Fixed: https://clusterfuzz.com/revisions?job=windows_asan_chrome_no_sandbox&range=555311:555312

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5366889069674496

Additional requirements: Requires Gestures

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Sign in to add a comment