New issue
Advanced search Search tips

Issue 877973 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Aug 29
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Float-cast-overflow in blink::LayoutFrameSet::UpdateLayout

Project Member Reported by ClusterFuzz, Aug 27

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=6035410044846080

Fuzzer: attekett_surku_fuzzer
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Float-cast-overflow
Crash Address: 
Crash State:
  blink::LayoutFrameSet::UpdateLayout
  blink::LayoutFrameSet::PositionFrames
  blink::LayoutFrameSet::UpdateLayout
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=551565:563900

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6035410044846080

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Aug 27

Components: Blink>Layout
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Cc: mstensho@chromium.org kojii@chromium.org kkaluri@chromium.org yosin@chromium.org
Labels: M-69 CF-NeedsTriage
Predator has provided 11 possible suspects

1. [cleanup] Remove Layout* dead code. by ikilpatrick@chromium.org
2. [LayoutNG] Add ComputedStyle::GetFontBaseline by kojii@chromium.org
3. [LayoutNG] Remove redundant invalidation at ObjectPaintInvalidator by yoichio@chromium.org
4. [css-contain] Disable paint containment in non-atomic inlines by rego@igalia.com
5. Simplify RootInlineBox::GetLogicalStart/EndBoxWithNode() by xiaochengh@chromium.org
6. [layoutng] Re-introduce optimization by cbiesinger@chromium.org
7. [LayoutNG] Introduce ReattachLegacyLayoutObjectList to replace NG objects to legacy objects by yosin@chromium.org
8. [LayoutNG] Skip special rules for child insertion in non-NG containers. by mstensho@chromium.org
9. [LayoutNG] Clean up #includes. by mstensho@chromium.org
10. [LayoutNG] Make Layout{BlockFlow,FlexibleBox}::CreateAnonymous() to take ComputedStyle by yosin@chromium.org
11. [LayoutNG] Fix baselines produced by block boxes by kojii@chromium.org


Unable to find the possible suspect, hence CC'ing few authors and adding "CF-NeedsTriage" label for further triage
Status: WontFix (was: Untriaged)
Numeric overflow without security implications are considered WontFix.
Project Member

Comment 4 by ClusterFuzz, Sep 5

Labels: Needs-Feedback
ClusterFuzz testcase 6035410044846080 is still reproducing on tip-of-tree build (trunk).

If this testcase was not reproducible locally or unworkable, ignore this notification and we will file another bug soon with hopefully a better and workable testcase.

Otherwise, if this is not intended to be fixed (e.g. this is an intentional crash), please add ClusterFuzz-Ignore label to prevent future bug filing with similar crash stacktrace.
Labels: ClusterFuzz-Ignore

Sign in to add a comment