[gap-decorations] Fix crash found by fuzzer in flex gap decorations#58334
Merged
chromium-wpt-export-bot merged 1 commit intomasterfrom Mar 7, 2026
Merged
[gap-decorations] Fix crash found by fuzzer in flex gap decorations#58334chromium-wpt-export-bot merged 1 commit intomasterfrom
chromium-wpt-export-bot merged 1 commit intomasterfrom
Conversation
Collaborator
Author
|
Close this PR because the Chromium CL does not have exportable changes. |
Collaborator
Author
|
Close this PR because the Chromium CL does not have exportable changes. |
There is a potential bug in the flex algorithm that causes a line of size 0 to be laid out. This causes the gap decorations code to create a `MainGap` for a line that does not exist, which then leads to a CHECK being hit when attempting to paint that `MainGap`. This CL simply adds a defensive check such that we don't create a main gap for cases such as this, where the line size is 0. A bug was filed for the algorithm behavior and I will attempt to address it in a followup CL Bug: 490343456 Fixed: 489948958 Change-Id: I62d3c568721bdfd3ed3dabff02087b350ccacf57 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7642513 Reviewed-by: Alison Maher <almaher@microsoft.com> Commit-Queue: Javier Contreras <javiercon@microsoft.com> Cr-Commit-Position: refs/heads/main@{#1595536}
ff8b97b to
6b6aae8
Compare
wpt-pr-bot
approved these changes
Mar 7, 2026
Collaborator
wpt-pr-bot
left a comment
There was a problem hiding this comment.
The review process for this patch is being conducted in the Chromium project.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
There is a potential bug in the flex algorithm that causes a line of
size 0 to be laid out. This causes the gap decorations code to create
a
MainGapfor a line that does not exist, which then leads to aCHECK being hit when attempting to paint that
MainGap. This CLsimply adds a defensive check such that we don't create a main gap
for cases such as this, where the line size is 0.
A bug was filed for the algorithm behavior and I will attempt to
address it in a followup CL
Bug: 490343456
Fixed: 489948958
Change-Id: I62d3c568721bdfd3ed3dabff02087b350ccacf57
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7642513
Reviewed-by: Alison Maher <almaher@microsoft.com>
Commit-Queue: Javier Contreras <javiercon@microsoft.com>
Cr-Commit-Position: refs/heads/main@{#1595536}