Float-cast-overflow in blink::TransformationMatrix::MapRect |
|||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5685819234582528 Fuzzer: inferno_twister_c Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Float-cast-overflow Crash Address: Crash State: blink::TransformationMatrix::MapRect SourceToDestinationRect<blink::FloatRect> blink::JankTracker::AccumulateJank Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=611321:611338 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5685819234582528 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for instructions to reproduce this bug locally.
,
Jan 3
Automatically adding ccs based on suspected regression changelists: Release canvas software image decode locks eagerly by enne@chromium.org - https://chromium.googlesource.com/chromium/src/+/80afcc8ccad7f767f47218860e45ecc376874785 Remove cold mode idle time spellchecker flag by xiaochengh@chromium.org - https://chromium.googlesource.com/chromium/src/+/070773549900baa6db6fcbd18aa710b81a461d34 If this is incorrect, please let us know why and apply the Test-Predator-Wrong-CLs label.
,
Jan 4
No problem with overflowing rectangle sizes in this code. |
|||
►
Sign in to add a comment |
|||
Comment 1 by ClusterFuzz
, Jan 3Labels: Test-Predator-Auto-Components