Fix Null-dereference READ in blink::Document::GetExecutionContext [chromium/src : main]

0 views
Skip to first unread message

Tarcísio Fischer (Gerrit)

unread,
Jan 27, 2026, 7:24:20 AM (4 days ago) Jan 27
to David Baron, Charlie Harrison, Chromium LUCI CQ, AyeAye, loading-rev...@chromium.org, kinuko...@chromium.org, blink-re...@chromium.org, blink-rev...@chromium.org, blink-...@chromium.org
Attention needed from Charlie Harrison and David Baron

Tarcísio Fischer added 1 comment

Patchset-level comments
File-level comment, Patchset 1 (Latest):
Tarcísio Fischer . resolved

Hey, all.

Is there any option to run that exact environment+test from the fuzzer here on CI?

Thanks in advance.

Open in Gerrit

Related details

Attention is currently required from:
  • Charlie Harrison
  • David Baron
Submit Requirements:
  • requirement satisfiedCode-Coverage
  • requirement is not satisfiedCode-Owners
  • requirement is not satisfiedCode-Review
  • requirement is not satisfiedReview-Enforcement
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: comment
Gerrit-Project: chromium/src
Gerrit-Branch: main
Gerrit-Change-Id: I1aa7e03fd86aa3a060b612eee1a7a82e8aae596f
Gerrit-Change-Number: 7520405
Gerrit-PatchSet: 1
Gerrit-Owner: Tarcísio Fischer <tarcisio...@arm.com>
Gerrit-Reviewer: Charlie Harrison <cshar...@chromium.org>
Gerrit-Reviewer: David Baron <dba...@chromium.org>
Gerrit-Reviewer: Tarcísio Fischer <tarcisio...@arm.com>
Gerrit-Attention: Charlie Harrison <cshar...@chromium.org>
Gerrit-Attention: David Baron <dba...@chromium.org>
Gerrit-Comment-Date: Tue, 27 Jan 2026 12:24:03 +0000
Gerrit-HasComments: Yes
Gerrit-Has-Labels: No
satisfied_requirement
unsatisfied_requirement
open
diffy

David Baron (Gerrit)

unread,
Jan 27, 2026, 11:47:44 AM (4 days ago) Jan 27
to Tarcísio Fischer, David Baron, Charlie Harrison, Chromium LUCI CQ, AyeAye, loading-rev...@chromium.org, kinuko...@chromium.org, blink-re...@chromium.org, blink-rev...@chromium.org, blink-...@chromium.org
Attention needed from Charlie Harrison and Tarcísio Fischer

David Baron added 2 comments

File third_party/blink/renderer/core/dom/document.cc
Line 7819, Patchset 1 (Latest):ExecutionContext* Document::GetExecutionContext() const {
David Baron . unresolved

This change isn't needed; Member::Get() should be fine if the pointer is null.

File third_party/blink/renderer/core/html/parser/html_document_parser.cc
Line 1831, Patchset 1 (Latest): // Seen CSP tag, but there is no document to check the CSP. Disallow preloads.
David Baron . unresolved

Maybe the comment should mention that `detach()` has already been called, given that that's what the comment above the definition of `GetDocument()` says.

Open in Gerrit

Related details

Attention is currently required from:
  • Charlie Harrison
  • Tarcísio Fischer
Submit Requirements:
    • requirement satisfiedCode-Coverage
    • requirement is not satisfiedCode-Owners
    • requirement is not satisfiedCode-Review
    • requirement is not satisfiedNo-Unresolved-Comments
    • requirement is not satisfiedReview-Enforcement
    Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
    Gerrit-MessageType: comment
    Gerrit-Project: chromium/src
    Gerrit-Branch: main
    Gerrit-Change-Id: I1aa7e03fd86aa3a060b612eee1a7a82e8aae596f
    Gerrit-Change-Number: 7520405
    Gerrit-PatchSet: 1
    Gerrit-Owner: Tarcísio Fischer <tarcisio...@arm.com>
    Gerrit-Reviewer: Charlie Harrison <cshar...@chromium.org>
    Gerrit-Reviewer: David Baron <dba...@chromium.org>
    Gerrit-Reviewer: Tarcísio Fischer <tarcisio...@arm.com>
    Gerrit-Attention: Tarcísio Fischer <tarcisio...@arm.com>
    Gerrit-Attention: Charlie Harrison <cshar...@chromium.org>
    Gerrit-Comment-Date: Tue, 27 Jan 2026 16:47:38 +0000
    Gerrit-HasComments: Yes
    Gerrit-Has-Labels: No
    satisfied_requirement
    unsatisfied_requirement
    open
    diffy

    Tarcísio Fischer (Gerrit)

    unread,
    Jan 29, 2026, 5:30:55 AM (2 days ago) Jan 29
    to David Baron, Charlie Harrison, Chromium LUCI CQ, AyeAye, loading-rev...@chromium.org, kinuko...@chromium.org, blink-re...@chromium.org, blink-rev...@chromium.org, blink-...@chromium.org
    Attention needed from Charlie Harrison and David Baron

    Tarcísio Fischer added 2 comments

    File third_party/blink/renderer/core/dom/document.cc
    Line 7819, Patchset 1:ExecutionContext* Document::GetExecutionContext() const {
    David Baron . resolved

    This change isn't needed; Member::Get() should be fine if the pointer is null.

    Tarcísio Fischer

    Done

    File third_party/blink/renderer/core/html/parser/html_document_parser.cc
    Line 1831, Patchset 1: // Seen CSP tag, but there is no document to check the CSP. Disallow preloads.
    David Baron . resolved

    Maybe the comment should mention that `detach()` has already been called, given that that's what the comment above the definition of `GetDocument()` says.

    Tarcísio Fischer

    Done

    Open in Gerrit

    Related details

    Attention is currently required from:
    • Charlie Harrison
    • David Baron
    Submit Requirements:
      • requirement satisfiedCode-Coverage
      • requirement is not satisfiedCode-Owners
      • requirement is not satisfiedCode-Review
      • requirement is not satisfiedReview-Enforcement
      Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
      Gerrit-MessageType: comment
      Gerrit-Project: chromium/src
      Gerrit-Branch: main
      Gerrit-Change-Id: I1aa7e03fd86aa3a060b612eee1a7a82e8aae596f
      Gerrit-Change-Number: 7520405
      Gerrit-PatchSet: 2
      Gerrit-Owner: Tarcísio Fischer <tarcisio...@arm.com>
      Gerrit-Reviewer: Charlie Harrison <cshar...@chromium.org>
      Gerrit-Reviewer: David Baron <dba...@chromium.org>
      Gerrit-Reviewer: Tarcísio Fischer <tarcisio...@arm.com>
      Gerrit-Attention: Charlie Harrison <cshar...@chromium.org>
      Gerrit-Attention: David Baron <dba...@chromium.org>
      Gerrit-Comment-Date: Thu, 29 Jan 2026 10:30:50 +0000
      Gerrit-HasComments: Yes
      Gerrit-Has-Labels: No
      Comment-In-Reply-To: David Baron <dba...@chromium.org>
      satisfied_requirement
      unsatisfied_requirement
      open
      diffy

      David Baron (Gerrit)

      unread,
      Jan 29, 2026, 10:36:00 AM (2 days ago) Jan 29
      to Tarcísio Fischer, David Baron, Charlie Harrison, Chromium LUCI CQ, AyeAye, loading-rev...@chromium.org, kinuko...@chromium.org, blink-re...@chromium.org, blink-rev...@chromium.org, blink-...@chromium.org
      Attention needed from Charlie Harrison and Tarcísio Fischer

      David Baron voted Code-Review+1

      Code-Review+1
      Open in Gerrit

      Related details

      Attention is currently required from:
      • Charlie Harrison
      • Tarcísio Fischer
      Submit Requirements:
      • requirement satisfiedCode-Coverage
      • requirement satisfiedCode-Owners
      • requirement is not satisfiedCode-Review
      • requirement is not satisfiedReview-Enforcement
      Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
      Gerrit-MessageType: comment
      Gerrit-Project: chromium/src
      Gerrit-Branch: main
      Gerrit-Change-Id: I1aa7e03fd86aa3a060b612eee1a7a82e8aae596f
      Gerrit-Change-Number: 7520405
      Gerrit-PatchSet: 2
      Gerrit-Owner: Tarcísio Fischer <tarcisio...@arm.com>
      Gerrit-Reviewer: Charlie Harrison <cshar...@chromium.org>
      Gerrit-Reviewer: David Baron <dba...@chromium.org>
      Gerrit-Reviewer: Tarcísio Fischer <tarcisio...@arm.com>
      Gerrit-Attention: Tarcísio Fischer <tarcisio...@arm.com>
      Gerrit-Attention: Charlie Harrison <cshar...@chromium.org>
      Gerrit-Comment-Date: Thu, 29 Jan 2026 15:35:47 +0000
      Gerrit-HasComments: No
      Gerrit-Has-Labels: Yes
      satisfied_requirement
      unsatisfied_requirement
      open
      diffy
      Reply all
      Reply to author
      Forward
      0 new messages