Float-cast-overflow in blink::LayoutFrameSet::UpdateLayout |
|||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=6035410044846080 Fuzzer: attekett_surku_fuzzer Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Float-cast-overflow Crash Address: Crash State: blink::LayoutFrameSet::UpdateLayout blink::LayoutFrameSet::PositionFrames blink::LayoutFrameSet::UpdateLayout Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=551565:563900 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6035410044846080 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Aug 28
Predator has provided 11 possible suspects 1. [cleanup] Remove Layout* dead code. by ikilpatrick@chromium.org 2. [LayoutNG] Add ComputedStyle::GetFontBaseline by kojii@chromium.org 3. [LayoutNG] Remove redundant invalidation at ObjectPaintInvalidator by yoichio@chromium.org 4. [css-contain] Disable paint containment in non-atomic inlines by rego@igalia.com 5. Simplify RootInlineBox::GetLogicalStart/EndBoxWithNode() by xiaochengh@chromium.org 6. [layoutng] Re-introduce optimization by cbiesinger@chromium.org 7. [LayoutNG] Introduce ReattachLegacyLayoutObjectList to replace NG objects to legacy objects by yosin@chromium.org 8. [LayoutNG] Skip special rules for child insertion in non-NG containers. by mstensho@chromium.org 9. [LayoutNG] Clean up #includes. by mstensho@chromium.org 10. [LayoutNG] Make Layout{BlockFlow,FlexibleBox}::CreateAnonymous() to take ComputedStyle by yosin@chromium.org 11. [LayoutNG] Fix baselines produced by block boxes by kojii@chromium.org Unable to find the possible suspect, hence CC'ing few authors and adding "CF-NeedsTriage" label for further triage
,
Aug 29
Numeric overflow without security implications are considered WontFix.
,
Sep 5
ClusterFuzz testcase 6035410044846080 is still reproducing on tip-of-tree build (trunk). If this testcase was not reproducible locally or unworkable, ignore this notification and we will file another bug soon with hopefully a better and workable testcase. Otherwise, if this is not intended to be fixed (e.g. this is an intentional crash), please add ClusterFuzz-Ignore label to prevent future bug filing with similar crash stacktrace.
,
Sep 7
|
|||||
►
Sign in to add a comment |
|||||
Comment 1 by ClusterFuzz
, Aug 27Labels: Test-Predator-Auto-Components