New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 854887 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Jul 4
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Bad-cast to blink::ScriptWrappable from invalid vptr in blink::V8Element::ToImpl

Project Member Reported by ClusterFuzz, Jun 21 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Showing comments 24 - 123 of 123 Older
Project Member

Comment 24 by ClusterFuzz, Jul 4

Labels: ClusterFuzz-Verified
Status: Verified (was: Started)
ClusterFuzz testcase 4596872245936128 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 25 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 26 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 27 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 28 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 29 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 30 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 31 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 32 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 33 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 34 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 35 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 36 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 37 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 38 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 39 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 40 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 41 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 42 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 43 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 44 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 45 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 46 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 47 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 48 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 49 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 50 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 51 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 52 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 53 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 54 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 55 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 56 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 57 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 58 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Labels: Merge-Request-68
Project Member

Comment 60 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 61 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 62 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 63 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 64 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 65 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 66 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 67 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 68 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 69 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 70 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 71 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 72 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 73 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 74 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 75 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 76 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 77 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 78 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 79 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 80 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 81 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 82 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 83 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 84 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 85 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 86 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 87 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 88 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 89 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 90 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Is ClusterFuzz broken? Comments after #13 look same.
Project Member

Comment 92 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 93 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 94 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 95 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 96 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 97 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 98 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 99 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 100 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 101 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 102 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 103 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Filed Issue 860124 for the ClusterFuzz spam.

Project Member

Comment 105 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 106 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 107 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 108 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 109 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 110 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 111 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 112 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 113 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 114 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 115 by ClusterFuzz, Jul 4

ClusterFuzz has detected this issue as fixed in range 572166:572167.

Detailed report: https://clusterfuzz.com/testcase?key=4596872245936128

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x23d3baf026f1
Crash State:
  Bad-cast to blink::ScriptWrappable from invalid vptr
  blink::V8Element::ToImpl
  blink::ScriptCustomElementDefinition::RunConstructor
  
Sanitizer: undefined (UBSAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=479114:479272
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=572166:572167

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4596872245936128

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 116 by sheriffbot@chromium.org, Jul 4

Labels: -Merge-Request-68 Hotlist-Merge-Review Merge-Review-68
This bug requires manual review: M68 has already been promoted to the beta branch, so this requires manual review
Please contact the milestone owner if you have questions.
Owners: cmasso@(Android), kariahda@(iOS), bhthompson@(ChromeOS), abdulsyed@(Desktop)

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 117 by sheriffbot@chromium.org, Jul 4

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Can you please comment on what needs to be merged here?
Cc: abdulsyed@chromium.org
abdulsyed@,
It's crrev.com/572167 in https://bugs.chromium.org/p/chromium/issues/detail?id=854887#c12

Labels: -Merge-Review-68 Merge-Approved-68
Approved - branch:3440
Project Member

Comment 121 by bugdroid1@chromium.org, Jul 10

Labels: -merge-approved-68 merge-merged-3440
The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/6ae11c1e45d4e8e6cde52f44f0b3f302eeae739b

commit 6ae11c1e45d4e8e6cde52f44f0b3f302eeae739b
Author: Kent Tamura <tkent@chromium.org>
Date: Tue Jul 10 03:37:31 2018

Merge "custom-element: Do not crash by Get(NewTarget, "prototype") failure." to M68 branch

https://html.spec.whatwg.org/multipage/dom.html#html-element-constructors
> 7. Let prototype be Get(NewTarget, "prototype"). Rethrow any exceptions.

As the specification says, we should rethrow. Removing a v8::TryCatch
instance in V8HTMLConstructor::HtmlConstructor() works as "rethrow".

Bug:  854887 
Change-Id: I6b2d6ae829453270fe4437a87e65528525c64990
Reviewed-on: https://chromium-review.googlesource.com/1124129
Reviewed-by: Yuki Shiino <yukishiino@chromium.org>
Reviewed-by: Kentaro Hara <haraken@chromium.org>
Reviewed-by: Hitoshi Yoshida <peria@chromium.org>
Commit-Queue: Kent Tamura <tkent@chromium.org>
Cr-Original-Commit-Position: refs/heads/master@{#572167}(cherry picked from commit 8381e35ca626c9853c6207de30828b7c3039430c)
Reviewed-on: https://chromium-review.googlesource.com/1130576
Reviewed-by: Kent Tamura <tkent@chromium.org>
Cr-Commit-Position: refs/branch-heads/3440@{#629}
Cr-Branched-From: 010ddcfda246975d194964ccf20038ebbdec6084-refs/heads/master@{#561733}
[add] https://crrev.com/6ae11c1e45d4e8e6cde52f44f0b3f302eeae739b/third_party/WebKit/LayoutTests/custom-elements/cereactions-with-exception-expected.txt
[add] https://crrev.com/6ae11c1e45d4e8e6cde52f44f0b3f302eeae739b/third_party/WebKit/LayoutTests/custom-elements/cereactions-with-exception.html
[modify] https://crrev.com/6ae11c1e45d4e8e6cde52f44f0b3f302eeae739b/third_party/blink/renderer/bindings/core/v8/v8_html_constructor.cc

Labels: Release-0-M68
Project Member

Comment 123 by sheriffbot@chromium.org, Oct 11

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Showing comments 24 - 123 of 123 Older

Sign in to add a comment