Issue metadata
Sign in to add a comment
|
Delete command crashes with :last-of-type and visibility:hidden |
||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5460349990731776 Fuzzer: ifratric-browserfuzzer-v3 Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: count <= MaxElementCountInBackingStore<T>() in heap_allocator.h blink::HeapAllocator::QuantizedSize<> blink::UndoStep::Append Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=523880:523906 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5460349990731776 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Apr 27 2018
Unable to provide possible suspect using Predator, CL and Code Search. This issue seems to be similar to the Issue 774255 . yosin@ -- Could you please take a look into this issue. Thanks!
,
Apr 27 2018
Lower to Pri-3 since this is caused by unusual HTML, :last-of-type selector with visibility: hidden.
,
Apr 27 2018
|
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by ClusterFuzz
, Apr 27 2018Labels: Test-Predator-Auto-Components