New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 843866 link

Starred by 4 users

Issue metadata

Status: WontFix
Owner: ----
Closed: May 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Mac
Pri: 1
Type: Bug



Sign in to add a comment

Null-dereference READ in blink::RootInlineBox::ClosestLeafChildForLogicalLeftPosition

Project Member Reported by ClusterFuzz, May 17 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5785590461890560

Fuzzer: ochang_domfuzzer
Job Type: linux_tsan_chrome_mp
Platform Id: linux

Crash Type: Null-dereference READ
Crash Address: 0x00000000003c
Crash State:
  blink::RootInlineBox::ClosestLeafChildForLogicalLeftPosition
  blink::RootInlineBox::ClosestLeafChildForPoint
  blink::NextLinePosition
  
Sanitizer: thread (TSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_tsan_chrome_mp&range=525734:525746

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5785590461890560

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, May 17 2018

Components: Blink>Editing Blink>Layout
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Cc: brajkumar@chromium.org
Labels: M-67 Test-Predator-Wrong
> Predator was unable to identify any culprit changelists for this test case. 

> Unable to find actual suspect through code search and also observing no possible CL under regression range, hence requesting someone from blink team to look in to it.

Thanks!

Labels: CF-NeedsTriage

Comment 4 by e...@chromium.org, May 17 2018

Status: WontFix (was: Untriaged)
Not a security issue and no reports in the wild. Closing as this code is going away.
Project Member

Comment 5 by ClusterFuzz, May 19 2018

Labels: OS-Windows
Project Member

Comment 6 by ClusterFuzz, May 24 2018

Labels: Needs-Feedback
ClusterFuzz testcase 5785590461890560 is still reproducing on tip-of-tree build (trunk).

If this testcase was not reproducible locally or unworkable, ignore this notification and we will file another bug soon with hopefully a better and workable testcase.

Otherwise, if this is not intended to be fixed (e.g. this is an intentional crash), please add ClusterFuzz-Ignore label to prevent future bug filing with similar crash stacktrace.
 Issue 848502  has been merged into this issue.
 Issue 849094  has been merged into this issue.
 Issue 849213  has been merged into this issue.
Project Member

Comment 10 by ClusterFuzz, Jun 5 2018

Labels: OS-Mac
 Issue 850024  has been merged into this issue.
 Issue 850438  has been merged into this issue.
Cc: pnangunoori@chromium.org
 Issue 851234  has been merged into this issue.

Sign in to add a comment