Fix Null-dereference READ in blink::Document::GetExecutionContext [chromium/src : main]

0 views
Skip to first unread message

Tarcísio Fischer (Gerrit)

unread,
Jan 27, 2026, 7:24:20 AMJan 27
to David Baron, Charlie Harrison, Chromium LUCI CQ, AyeAye, loading-rev...@chromium.org, kinuko...@chromium.org, blink-re...@chromium.org, blink-rev...@chromium.org, blink-...@chromium.org
Attention needed from Charlie Harrison and David Baron

Tarcísio Fischer added 1 comment

Patchset-level comments
File-level comment, Patchset 1 (Latest):
Tarcísio Fischer . resolved

Hey, all.

Is there any option to run that exact environment+test from the fuzzer here on CI?

Thanks in advance.

Open in Gerrit

Related details

Attention is currently required from:
  • Charlie Harrison
  • David Baron
Submit Requirements:
  • requirement satisfiedCode-Coverage
  • requirement is not satisfiedCode-Owners
  • requirement is not satisfiedCode-Review
  • requirement is not satisfiedReview-Enforcement
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: comment
Gerrit-Project: chromium/src
Gerrit-Branch: main
Gerrit-Change-Id: I1aa7e03fd86aa3a060b612eee1a7a82e8aae596f
Gerrit-Change-Number: 7520405
Gerrit-PatchSet: 1
Gerrit-Owner: Tarcísio Fischer <tarcisio...@arm.com>
Gerrit-Reviewer: Charlie Harrison <cshar...@chromium.org>
Gerrit-Reviewer: David Baron <dba...@chromium.org>
Gerrit-Reviewer: Tarcísio Fischer <tarcisio...@arm.com>
Gerrit-Attention: Charlie Harrison <cshar...@chromium.org>
Gerrit-Attention: David Baron <dba...@chromium.org>
Gerrit-Comment-Date: Tue, 27 Jan 2026 12:24:03 +0000
Gerrit-HasComments: Yes
Gerrit-Has-Labels: No
satisfied_requirement
unsatisfied_requirement
open
diffy

David Baron (Gerrit)

unread,
Jan 27, 2026, 11:47:44 AMJan 27
to Tarcísio Fischer, David Baron, Charlie Harrison, Chromium LUCI CQ, AyeAye, loading-rev...@chromium.org, kinuko...@chromium.org, blink-re...@chromium.org, blink-rev...@chromium.org, blink-...@chromium.org
Attention needed from Charlie Harrison and Tarcísio Fischer

David Baron added 2 comments

File third_party/blink/renderer/core/dom/document.cc
Line 7819, Patchset 1 (Latest):ExecutionContext* Document::GetExecutionContext() const {
David Baron . unresolved

This change isn't needed; Member::Get() should be fine if the pointer is null.

File third_party/blink/renderer/core/html/parser/html_document_parser.cc
Line 1831, Patchset 1 (Latest): // Seen CSP tag, but there is no document to check the CSP. Disallow preloads.
David Baron . unresolved

Maybe the comment should mention that `detach()` has already been called, given that that's what the comment above the definition of `GetDocument()` says.

Open in Gerrit

Related details

Attention is currently required from:
  • Charlie Harrison
  • Tarcísio Fischer
Submit Requirements:
    • requirement satisfiedCode-Coverage
    • requirement is not satisfiedCode-Owners
    • requirement is not satisfiedCode-Review
    • requirement is not satisfiedNo-Unresolved-Comments
    • requirement is not satisfiedReview-Enforcement
    Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
    Gerrit-MessageType: comment
    Gerrit-Project: chromium/src
    Gerrit-Branch: main
    Gerrit-Change-Id: I1aa7e03fd86aa3a060b612eee1a7a82e8aae596f
    Gerrit-Change-Number: 7520405
    Gerrit-PatchSet: 1
    Gerrit-Owner: Tarcísio Fischer <tarcisio...@arm.com>
    Gerrit-Reviewer: Charlie Harrison <cshar...@chromium.org>
    Gerrit-Reviewer: David Baron <dba...@chromium.org>
    Gerrit-Reviewer: Tarcísio Fischer <tarcisio...@arm.com>
    Gerrit-Attention: Tarcísio Fischer <tarcisio...@arm.com>
    Gerrit-Attention: Charlie Harrison <cshar...@chromium.org>
    Gerrit-Comment-Date: Tue, 27 Jan 2026 16:47:38 +0000
    Gerrit-HasComments: Yes
    Gerrit-Has-Labels: No
    satisfied_requirement
    unsatisfied_requirement
    open
    diffy

    Tarcísio Fischer (Gerrit)

    unread,
    Jan 29, 2026, 5:30:55 AMJan 29
    to David Baron, Charlie Harrison, Chromium LUCI CQ, AyeAye, loading-rev...@chromium.org, kinuko...@chromium.org, blink-re...@chromium.org, blink-rev...@chromium.org, blink-...@chromium.org
    Attention needed from Charlie Harrison and David Baron

    Tarcísio Fischer added 2 comments

    File third_party/blink/renderer/core/dom/document.cc
    Line 7819, Patchset 1:ExecutionContext* Document::GetExecutionContext() const {
    David Baron . resolved

    This change isn't needed; Member::Get() should be fine if the pointer is null.

    Tarcísio Fischer

    Done

    File third_party/blink/renderer/core/html/parser/html_document_parser.cc
    Line 1831, Patchset 1: // Seen CSP tag, but there is no document to check the CSP. Disallow preloads.
    David Baron . resolved

    Maybe the comment should mention that `detach()` has already been called, given that that's what the comment above the definition of `GetDocument()` says.

    Tarcísio Fischer

    Done

    Open in Gerrit

    Related details

    Attention is currently required from:
    • Charlie Harrison
    • David Baron
    Submit Requirements:
      • requirement satisfiedCode-Coverage
      • requirement is not satisfiedCode-Owners
      • requirement is not satisfiedCode-Review
      • requirement is not satisfiedReview-Enforcement
      Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
      Gerrit-MessageType: comment
      Gerrit-Project: chromium/src
      Gerrit-Branch: main
      Gerrit-Change-Id: I1aa7e03fd86aa3a060b612eee1a7a82e8aae596f
      Gerrit-Change-Number: 7520405
      Gerrit-PatchSet: 2
      Gerrit-Owner: Tarcísio Fischer <tarcisio...@arm.com>
      Gerrit-Reviewer: Charlie Harrison <cshar...@chromium.org>
      Gerrit-Reviewer: David Baron <dba...@chromium.org>
      Gerrit-Reviewer: Tarcísio Fischer <tarcisio...@arm.com>
      Gerrit-Attention: Charlie Harrison <cshar...@chromium.org>
      Gerrit-Attention: David Baron <dba...@chromium.org>
      Gerrit-Comment-Date: Thu, 29 Jan 2026 10:30:50 +0000
      Gerrit-HasComments: Yes
      Gerrit-Has-Labels: No
      Comment-In-Reply-To: David Baron <dba...@chromium.org>
      satisfied_requirement
      unsatisfied_requirement
      open
      diffy

      David Baron (Gerrit)

      unread,
      Jan 29, 2026, 10:36:00 AMJan 29
      to Tarcísio Fischer, David Baron, Charlie Harrison, Chromium LUCI CQ, AyeAye, loading-rev...@chromium.org, kinuko...@chromium.org, blink-re...@chromium.org, blink-rev...@chromium.org, blink-...@chromium.org
      Attention needed from Charlie Harrison and Tarcísio Fischer

      David Baron voted Code-Review+1

      Code-Review+1
      Open in Gerrit

      Related details

      Attention is currently required from:
      • Charlie Harrison
      • Tarcísio Fischer
      Submit Requirements:
      • requirement satisfiedCode-Coverage
      • requirement satisfiedCode-Owners
      • requirement is not satisfiedCode-Review
      • requirement is not satisfiedReview-Enforcement
      Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
      Gerrit-MessageType: comment
      Gerrit-Project: chromium/src
      Gerrit-Branch: main
      Gerrit-Change-Id: I1aa7e03fd86aa3a060b612eee1a7a82e8aae596f
      Gerrit-Change-Number: 7520405
      Gerrit-PatchSet: 2
      Gerrit-Owner: Tarcísio Fischer <tarcisio...@arm.com>
      Gerrit-Reviewer: Charlie Harrison <cshar...@chromium.org>
      Gerrit-Reviewer: David Baron <dba...@chromium.org>
      Gerrit-Reviewer: Tarcísio Fischer <tarcisio...@arm.com>
      Gerrit-Attention: Tarcísio Fischer <tarcisio...@arm.com>
      Gerrit-Attention: Charlie Harrison <cshar...@chromium.org>
      Gerrit-Comment-Date: Thu, 29 Jan 2026 15:35:47 +0000
      Gerrit-HasComments: No
      Gerrit-Has-Labels: Yes
      satisfied_requirement
      unsatisfied_requirement
      open
      diffy

      Tarcísio Fischer (Gerrit)

      unread,
      Feb 18, 2026, 9:31:07 AM (2 days ago) Feb 18
      to David Baron, Charlie Harrison, Chromium LUCI CQ, AyeAye, loading-rev...@chromium.org, kinuko...@chromium.org, blink-re...@chromium.org, blink-rev...@chromium.org, blink-...@chromium.org
      Attention needed from Charlie Harrison

      Tarcísio Fischer added 1 comment

      Patchset-level comments
      File-level comment, Patchset 2 (Latest):
      Tarcísio Fischer . resolved

      Gentle bump on this @cshar...@chromium.org if you have the time to take a look, please :)

      Open in Gerrit

      Related details

      Attention is currently required from:
      • Charlie Harrison
      Submit Requirements:
      • requirement satisfiedCode-Coverage
      • requirement satisfiedCode-Owners
      • requirement is not satisfiedCode-Review
      • requirement is not satisfiedReview-Enforcement
      Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
      Gerrit-MessageType: comment
      Gerrit-Project: chromium/src
      Gerrit-Branch: main
      Gerrit-Change-Id: I1aa7e03fd86aa3a060b612eee1a7a82e8aae596f
      Gerrit-Change-Number: 7520405
      Gerrit-PatchSet: 2
      Gerrit-Owner: Tarcísio Fischer <tarcisio...@arm.com>
      Gerrit-Reviewer: Charlie Harrison <cshar...@chromium.org>
      Gerrit-Reviewer: David Baron <dba...@chromium.org>
      Gerrit-Reviewer: Tarcísio Fischer <tarcisio...@arm.com>
      Gerrit-Attention: Charlie Harrison <cshar...@chromium.org>
      Gerrit-Comment-Date: Wed, 18 Feb 2026 14:30:52 +0000
      Gerrit-HasComments: Yes
      Gerrit-Has-Labels: No
      satisfied_requirement
      unsatisfied_requirement
      open
      diffy

      Mason Freed (Gerrit)

      unread,
      Feb 18, 2026, 12:55:12 PM (2 days ago) Feb 18
      to Tarcísio Fischer, David Baron, Charlie Harrison, Chromium LUCI CQ, AyeAye, loading-rev...@chromium.org, kinuko...@chromium.org, blink-re...@chromium.org, blink-rev...@chromium.org, blink-...@chromium.org
      Attention needed from Charlie Harrison and Tarcísio Fischer

      Mason Freed voted and added 1 comment

      Votes added by Mason Freed

      Code-Review+1

      1 comment

      Patchset-level comments
      Mason Freed . resolved

      This LGTM

      Open in Gerrit

      Related details

      Attention is currently required from:
      • Charlie Harrison
      • Tarcísio Fischer
      Submit Requirements:
        • requirement satisfiedCode-Coverage
        • requirement satisfiedCode-Owners
        • requirement satisfiedCode-Review
        • requirement satisfiedReview-Enforcement
        Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
        Gerrit-MessageType: comment
        Gerrit-Project: chromium/src
        Gerrit-Branch: main
        Gerrit-Change-Id: I1aa7e03fd86aa3a060b612eee1a7a82e8aae596f
        Gerrit-Change-Number: 7520405
        Gerrit-PatchSet: 2
        Gerrit-Owner: Tarcísio Fischer <tarcisio...@arm.com>
        Gerrit-Reviewer: Charlie Harrison <cshar...@chromium.org>
        Gerrit-Reviewer: David Baron <dba...@chromium.org>
        Gerrit-Reviewer: Mason Freed <mas...@chromium.org>
        Gerrit-Reviewer: Tarcísio Fischer <tarcisio...@arm.com>
        Gerrit-Attention: Tarcísio Fischer <tarcisio...@arm.com>
        Gerrit-Attention: Charlie Harrison <cshar...@chromium.org>
        Gerrit-Comment-Date: Wed, 18 Feb 2026 17:55:02 +0000
        Gerrit-HasComments: Yes
        Gerrit-Has-Labels: Yes
        satisfied_requirement
        open
        diffy

        Charlie Harrison (Gerrit)

        unread,
        Feb 18, 2026, 1:17:41 PM (2 days ago) Feb 18
        to Tarcísio Fischer, Mason Freed, David Baron, Chromium LUCI CQ, AyeAye, loading-rev...@chromium.org, kinuko...@chromium.org, blink-re...@chromium.org, blink-rev...@chromium.org, blink-...@chromium.org
        Attention needed from Tarcísio Fischer

        Charlie Harrison voted and added 1 comment

        Votes added by Charlie Harrison

        Code-Review+1

        1 comment

        Patchset-level comments
        Charlie Harrison . resolved

        Oops sorry!

        Open in Gerrit

        Related details

        Attention is currently required from:
        • Tarcísio Fischer
        Submit Requirements:
        • requirement satisfiedCode-Coverage
        • requirement satisfiedCode-Owners
        • requirement satisfiedCode-Review
        • requirement satisfiedReview-Enforcement
        Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
        Gerrit-MessageType: comment
        Gerrit-Project: chromium/src
        Gerrit-Branch: main
        Gerrit-Change-Id: I1aa7e03fd86aa3a060b612eee1a7a82e8aae596f
        Gerrit-Change-Number: 7520405
        Gerrit-PatchSet: 2
        Gerrit-Owner: Tarcísio Fischer <tarcisio...@arm.com>
        Gerrit-Reviewer: Charlie Harrison <cshar...@chromium.org>
        Gerrit-Reviewer: David Baron <dba...@chromium.org>
        Gerrit-Reviewer: Mason Freed <mas...@chromium.org>
        Gerrit-Reviewer: Tarcísio Fischer <tarcisio...@arm.com>
        Gerrit-Attention: Tarcísio Fischer <tarcisio...@arm.com>
        Gerrit-Comment-Date: Wed, 18 Feb 2026 18:17:30 +0000
        Gerrit-HasComments: Yes
        Gerrit-Has-Labels: Yes
        satisfied_requirement
        open
        diffy

        Tarcísio Fischer (Gerrit)

        unread,
        Feb 19, 2026, 3:45:57 AM (yesterday) Feb 19
        to Charlie Harrison, Mason Freed, David Baron, Chromium LUCI CQ, AyeAye, loading-rev...@chromium.org, kinuko...@chromium.org, blink-re...@chromium.org, blink-rev...@chromium.org, blink-...@chromium.org
        Attention needed from Charlie Harrison, David Baron and Mason Freed

        Tarcísio Fischer added 1 comment

        Patchset-level comments
        Tarcísio Fischer . resolved

        Thanks all for the review.

        I don't have the credentials to merge, could someone please merge this for me?
        Thanks in advance!

        Open in Gerrit

        Related details

        Attention is currently required from:
        • Charlie Harrison
        • David Baron
        • Mason Freed
        Submit Requirements:
        • requirement satisfiedCode-Coverage
        • requirement satisfiedCode-Owners
        • requirement satisfiedCode-Review
        • requirement satisfiedReview-Enforcement
        Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
        Gerrit-MessageType: comment
        Gerrit-Project: chromium/src
        Gerrit-Branch: main
        Gerrit-Change-Id: I1aa7e03fd86aa3a060b612eee1a7a82e8aae596f
        Gerrit-Change-Number: 7520405
        Gerrit-PatchSet: 2
        Gerrit-Owner: Tarcísio Fischer <tarcisio...@arm.com>
        Gerrit-Reviewer: Charlie Harrison <cshar...@chromium.org>
        Gerrit-Reviewer: David Baron <dba...@chromium.org>
        Gerrit-Reviewer: Mason Freed <mas...@chromium.org>
        Gerrit-Reviewer: Tarcísio Fischer <tarcisio...@arm.com>
        Gerrit-Attention: Mason Freed <mas...@chromium.org>
        Gerrit-Attention: Charlie Harrison <cshar...@chromium.org>
        Gerrit-Attention: David Baron <dba...@chromium.org>
        Gerrit-Comment-Date: Thu, 19 Feb 2026 08:45:37 +0000
        Gerrit-HasComments: Yes
        Gerrit-Has-Labels: No
        satisfied_requirement
        open
        diffy

        David Baron (Gerrit)

        unread,
        Feb 19, 2026, 9:42:04 AM (yesterday) Feb 19
        to Tarcísio Fischer, David Baron, Charlie Harrison, Mason Freed, Chromium LUCI CQ, AyeAye, loading-rev...@chromium.org, kinuko...@chromium.org, blink-re...@chromium.org, blink-rev...@chromium.org, blink-...@chromium.org
        Attention needed from Charlie Harrison, Mason Freed and Tarcísio Fischer

        David Baron voted Commit-Queue+2

        Commit-Queue+2
        Open in Gerrit

        Related details

        Attention is currently required from:
        • Charlie Harrison
        • Mason Freed
        • Tarcísio Fischer
        Submit Requirements:
        • requirement satisfiedCode-Coverage
        • requirement satisfiedCode-Owners
        • requirement satisfiedCode-Review
        • requirement satisfiedReview-Enforcement
        Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
        Gerrit-MessageType: comment
        Gerrit-Project: chromium/src
        Gerrit-Branch: main
        Gerrit-Change-Id: I1aa7e03fd86aa3a060b612eee1a7a82e8aae596f
        Gerrit-Change-Number: 7520405
        Gerrit-PatchSet: 2
        Gerrit-Owner: Tarcísio Fischer <tarcisio...@arm.com>
        Gerrit-Reviewer: Charlie Harrison <cshar...@chromium.org>
        Gerrit-Reviewer: David Baron <dba...@chromium.org>
        Gerrit-Reviewer: Mason Freed <mas...@chromium.org>
        Gerrit-Reviewer: Tarcísio Fischer <tarcisio...@arm.com>
        Gerrit-Attention: Tarcísio Fischer <tarcisio...@arm.com>
        Gerrit-Attention: Mason Freed <mas...@chromium.org>
        Gerrit-Attention: Charlie Harrison <cshar...@chromium.org>
        Gerrit-Comment-Date: Thu, 19 Feb 2026 14:41:56 +0000
        Gerrit-HasComments: No
        Gerrit-Has-Labels: Yes
        satisfied_requirement
        open
        diffy

        Chromium LUCI CQ (Gerrit)

        unread,
        Feb 19, 2026, 10:34:43 AM (yesterday) Feb 19
        to Tarcísio Fischer, David Baron, Charlie Harrison, Mason Freed, AyeAye, loading-rev...@chromium.org, kinuko...@chromium.org, blink-re...@chromium.org, blink-rev...@chromium.org, blink-...@chromium.org

        Chromium LUCI CQ submitted the change

        Change information

        Commit message:
        Fix Null-dereference READ in blink::Document::GetExecutionContext
        Bug: 469851573
        Change-Id: I1aa7e03fd86aa3a060b612eee1a7a82e8aae596f
        Reviewed-by: David Baron <dba...@chromium.org>
        Commit-Queue: David Baron <dba...@chromium.org>
        Reviewed-by: Charlie Harrison <cshar...@chromium.org>
        Reviewed-by: Mason Freed <mas...@chromium.org>
        Cr-Commit-Position: refs/heads/main@{#1587117}
        Files:
        • M third_party/blink/renderer/core/html/parser/html_document_parser.cc
        Change size: XS
        Delta: 1 file changed, 8 insertions(+), 1 deletion(-)
        Branch: refs/heads/main
        Submit Requirements:
        • requirement satisfiedCode-Review: +1 by Charlie Harrison, +1 by David Baron, +1 by Mason Freed
        Open in Gerrit
        Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
        Gerrit-MessageType: merged
        Gerrit-Project: chromium/src
        Gerrit-Branch: main
        Gerrit-Change-Id: I1aa7e03fd86aa3a060b612eee1a7a82e8aae596f
        Gerrit-Change-Number: 7520405
        Gerrit-PatchSet: 3
        Gerrit-Owner: Tarcísio Fischer <tarcisio...@arm.com>
        Gerrit-Reviewer: Charlie Harrison <cshar...@chromium.org>
        Gerrit-Reviewer: Chromium LUCI CQ <chromiu...@luci-project-accounts.iam.gserviceaccount.com>
        open
        diffy
        satisfied_requirement
        Reply all
        Reply to author
        Forward
        0 new messages