<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>106237</bug_id>
          
          <creation_ts>2013-01-07 11:18:03 -0800</creation_ts>
          <short_desc>REGRESSION(r137632): Caused major security regressions on ClusterFuzz (Requested by inferno-sec on #webkit).</short_desc>
          <delta_ts>2013-01-07 11:54:25 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>New Bugs</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          <blocked>103750</blocked>
          <everconfirmed>1</everconfirmed>
          <reporter name="WebKit Review Bot">webkit.review.bot</reporter>
          <assigned_to name="WebKit Review Bot">webkit.review.bot</assigned_to>
          <cc>dbarton</cc>
    
    <cc>inferno</cc>
    
    <cc>tony</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>801460</commentid>
    <comment_count>0</comment_count>
    <who name="WebKit Review Bot">webkit.review.bot</who>
    <bug_when>2013-01-07 11:18:03 -0800</bug_when>
    <thetext>http://trac.webkit.org/changeset/137632 broke the build:
Caused major security regressions on ClusterFuzz (Requested by inferno-sec on #webkit).

This is an automatic bug report generated by the sheriff-bot. If this bug
report was created because of a flaky test, please file a bug for the flaky
test (if we don&apos;t already have one on file) and dup this bug against that bug
so that we can track how often these flaky tests case pain.

&quot;Only you can prevent forest fires.&quot; -- Smokey the Bear</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>801463</commentid>
    <comment_count>1</comment_count>
      <attachid>181536</attachid>
    <who name="WebKit Review Bot">webkit.review.bot</who>
    <bug_when>2013-01-07 11:18:47 -0800</bug_when>
    <thetext>Created attachment 181536
ROLLOUT of r137632

Any committer can land this patch automatically by marking it commit-queue+.  The commit-queue will build and test the patch before landing to ensure that the rollout will be successful.  This process takes approximately 15 minutes.

If you would like to land the rollout faster, you can use the following command:

  webkit-patch land-attachment ATTACHMENT_ID

where ATTACHMENT_ID is the ID of this attachment.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>801490</commentid>
    <comment_count>2</comment_count>
      <attachid>181536</attachid>
    <who name="WebKit Review Bot">webkit.review.bot</who>
    <bug_when>2013-01-07 11:42:31 -0800</bug_when>
    <thetext>Comment on attachment 181536
ROLLOUT of r137632

Rejecting attachment 181536 from commit-queue.

Failed to run &quot;[u&apos;/mnt/git/webkit-commit-queue/Tools/Scripts/webkit-patch&apos;, u&apos;--status-host=queues.webkit.org&apos;, ...&quot; exit_code: 2 cwd: /mnt/git/webkit-commit-queue

Last 500 characters of output:
commit-queue/Source/WebKit/chromium/third_party/v8-i18n --revision 159 --non-interactive --force --accept theirs-conflict --ignore-externals&apos; in &apos;/mnt/git/webkit-commit-queue/Source/WebKit/chromium&apos;
50&gt;At revision 159.

________ running &apos;/usr/bin/python tools/clang/scripts/update.py --mac-only&apos; in &apos;/mnt/git/webkit-commit-queue/Source/WebKit/chromium&apos;

________ running &apos;/usr/bin/python gyp_webkit&apos; in &apos;/mnt/git/webkit-commit-queue/Source/WebKit/chromium&apos;
Updating webkit projects from gyp files...

Full output: http://queues.webkit.org/results/15744671</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>801504</commentid>
    <comment_count>3</comment_count>
      <attachid>181536</attachid>
    <who name="Abhishek Arya">inferno</who>
    <bug_when>2013-01-07 11:54:23 -0800</bug_when>
    <thetext>Comment on attachment 181536
ROLLOUT of r137632

Clearing flags on attachment: 181536

Committed r138974: &lt;http://trac.webkit.org/changeset/138974&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>801505</commentid>
    <comment_count>4</comment_count>
    <who name="Abhishek Arya">inferno</who>
    <bug_when>2013-01-07 11:54:25 -0800</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>181536</attachid>
            <date>2013-01-07 11:18:47 -0800</date>
            <delta_ts>2013-01-07 11:54:23 -0800</delta_ts>
            <desc>ROLLOUT of r137632</desc>
            <filename>bug-106237-20130107192528.patch</filename>
            <type>text/plain</type>
            <size>5311</size>
            <attacher name="WebKit Review Bot">webkit.review.bot</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogMTM4OTY1CmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViQ29yZS9D
aGFuZ2VMb2cgYi9Tb3VyY2UvV2ViQ29yZS9DaGFuZ2VMb2cKaW5kZXggNDU1YTkzOGI5NjkyM2Zm
NDA5MGE1NTZkMWQ5YjVjMmE0OGMxMTA1ZC4uMDQyYTVhOTRmZjQ4NGZjZWIzOGY0YjgzOTJlMDI0
MWM2YTYxZTJmNSAxMDA2NDQKLS0tIGEvU291cmNlL1dlYkNvcmUvQ2hhbmdlTG9nCisrKyBiL1Nv
dXJjZS9XZWJDb3JlL0NoYW5nZUxvZwpAQCAtMSwzICsxLDE2IEBACisyMDEzLTAxLTA3ICBTaGVy
aWZmIEJvdCAgPHdlYmtpdC5yZXZpZXcuYm90QGdtYWlsLmNvbT4KKworICAgICAgICBVbnJldmll
d2VkLCByb2xsaW5nIG91dCByMTM3NjMyLgorICAgICAgICBodHRwOi8vdHJhYy53ZWJraXQub3Jn
L2NoYW5nZXNldC8xMzc2MzIKKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19i
dWcuY2dpP2lkPTEwNjIzNworCisgICAgICAgIENhdXNlZCBtYWpvciBzZWN1cml0eSByZWdyZXNz
aW9ucyBvbiBDbHVzdGVyRnV6eiAoUmVxdWVzdGVkIGJ5CisgICAgICAgIGluZmVybm8tc2VjIG9u
ICN3ZWJraXQpLgorCisgICAgICAgICogcmVuZGVyaW5nL1JlbmRlckJsb2NrLmNwcDoKKyAgICAg
ICAgKFdlYkNvcmU6OlJlbmRlckJsb2NrOjpzdGFydERlbGF5VXBkYXRlU2Nyb2xsSW5mbyk6Cisg
ICAgICAgIChXZWJDb3JlOjpSZW5kZXJCbG9jazo6ZmluaXNoRGVsYXlVcGRhdGVTY3JvbGxJbmZv
KToKKwogMjAxMy0wMS0wNyAgTWljaGFlbCBQcnVldHQgIDxtaWNoYWVsQDY4ay5vcmc+CiAKICAg
ICAgICAgW0pTQ10gQ29weSBub24taW5kZXggcHJvcGVydGllcyBvZiBhcnJheXMgaW4gU2VyaWFs
aXplZFNjcmlwdFZhbHVlCmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViQ29yZS9yZW5kZXJpbmcvUmVu
ZGVyQmxvY2suY3BwIGIvU291cmNlL1dlYkNvcmUvcmVuZGVyaW5nL1JlbmRlckJsb2NrLmNwcApp
bmRleCBjNDlkMjVjNTQ4Y2RkYTI3MGFmNmY5YTcwNzFmNGEyODQ4NmQzNDU3Li5jNDkxMWI4ZGEw
ZmM5ZGQ0ODk3NzljYzhiZjE3NzhjYTAzYWUyNTViIDEwMDY0NAotLS0gYS9Tb3VyY2UvV2ViQ29y
ZS9yZW5kZXJpbmcvUmVuZGVyQmxvY2suY3BwCisrKyBiL1NvdXJjZS9XZWJDb3JlL3JlbmRlcmlu
Zy9SZW5kZXJCbG9jay5jcHAKQEAgLTEyODYsOCArMTI4Niw4IEBAIGJvb2wgUmVuZGVyQmxvY2s6
OmlzU2VsZkNvbGxhcHNpbmdCbG9jaygpIGNvbnN0CiAKIHZvaWQgUmVuZGVyQmxvY2s6OnN0YXJ0
RGVsYXlVcGRhdGVTY3JvbGxJbmZvKCkKIHsKLSAgICBpZiAoIWdEZWxheWVkVXBkYXRlU2Nyb2xs
SW5mb1NldCkgewotICAgICAgICBBU1NFUlQoIWdEZWxheVVwZGF0ZVNjcm9sbEluZm8pOworICAg
IGlmIChnRGVsYXlVcGRhdGVTY3JvbGxJbmZvID09IDApIHsKKyAgICAgICAgQVNTRVJUKCFnRGVs
YXllZFVwZGF0ZVNjcm9sbEluZm9TZXQpOwogICAgICAgICBnRGVsYXllZFVwZGF0ZVNjcm9sbElu
Zm9TZXQgPSBuZXcgRGVsYXllZFVwZGF0ZVNjcm9sbEluZm9TZXQ7CiAgICAgfQogICAgIEFTU0VS
VChnRGVsYXllZFVwZGF0ZVNjcm9sbEluZm9TZXQpOwpAQCAtMTMwMSwyMiArMTMwMSwxNSBAQCB2
b2lkIFJlbmRlckJsb2NrOjpmaW5pc2hEZWxheVVwZGF0ZVNjcm9sbEluZm8oKQogICAgIGlmIChn
RGVsYXlVcGRhdGVTY3JvbGxJbmZvID09IDApIHsKICAgICAgICAgQVNTRVJUKGdEZWxheWVkVXBk
YXRlU2Nyb2xsSW5mb1NldCk7CiAKLSAgICAgICAgVmVjdG9yPFJlbmRlckJsb2NrKj4gaW5mb1Nl
dDsKLSAgICAgICAgd2hpbGUgKGdEZWxheWVkVXBkYXRlU2Nyb2xsSW5mb1NldCAmJiBnRGVsYXll
ZFVwZGF0ZVNjcm9sbEluZm9TZXQtPnNpemUoKSkgewotICAgICAgICAgICAgY29weVRvVmVjdG9y
KCpnRGVsYXllZFVwZGF0ZVNjcm9sbEluZm9TZXQsIGluZm9TZXQpOwotICAgICAgICAgICAgZm9y
IChWZWN0b3I8UmVuZGVyQmxvY2sqPjo6aXRlcmF0b3IgaXQgPSBpbmZvU2V0LmJlZ2luKCk7IGl0
ICE9IGluZm9TZXQuZW5kKCk7ICsraXQpIHsKLSAgICAgICAgICAgICAgICBSZW5kZXJCbG9jayog
YmxvY2sgPSAqaXQ7Ci0gICAgICAgICAgICAgICAgLy8gfGJsb2NrfCBtYXkgaGF2ZSBiZWVuIGRl
c3Ryb3llZCBhdCB0aGlzIHBvaW50LCBidXQgdGhlbiBpdCB3aWxsIGhhdmUgYmVlbiByZW1vdmVk
IGZyb20gZ0RlbGF5ZWRVcGRhdGVTY3JvbGxJbmZvU2V0LgotICAgICAgICAgICAgICAgIGlmIChn
RGVsYXllZFVwZGF0ZVNjcm9sbEluZm9TZXQgJiYgZ0RlbGF5ZWRVcGRhdGVTY3JvbGxJbmZvU2V0
LT5jb250YWlucyhibG9jaykpIHsKLSAgICAgICAgICAgICAgICAgICAgZ0RlbGF5ZWRVcGRhdGVT
Y3JvbGxJbmZvU2V0LT5yZW1vdmUoYmxvY2spOwotICAgICAgICAgICAgICAgICAgICBpZiAoYmxv
Y2stPmhhc092ZXJmbG93Q2xpcCgpKQotICAgICAgICAgICAgICAgICAgICAgICAgYmxvY2stPmxh
eWVyKCktPnVwZGF0ZVNjcm9sbEluZm9BZnRlckxheW91dCgpOwotICAgICAgICAgICAgICAgIH0K
KyAgICAgICAgT3duUHRyPERlbGF5ZWRVcGRhdGVTY3JvbGxJbmZvU2V0PiBpbmZvU2V0KGFkb3B0
UHRyKGdEZWxheWVkVXBkYXRlU2Nyb2xsSW5mb1NldCkpOworICAgICAgICBnRGVsYXllZFVwZGF0
ZVNjcm9sbEluZm9TZXQgPSAwOworCisgICAgICAgIGZvciAoRGVsYXllZFVwZGF0ZVNjcm9sbElu
Zm9TZXQ6Oml0ZXJhdG9yIGl0ID0gaW5mb1NldC0+YmVnaW4oKTsgaXQgIT0gaW5mb1NldC0+ZW5k
KCk7ICsraXQpIHsKKyAgICAgICAgICAgIFJlbmRlckJsb2NrKiBibG9jayA9ICppdDsKKyAgICAg
ICAgICAgIGlmIChibG9jay0+aGFzT3ZlcmZsb3dDbGlwKCkpIHsKKyAgICAgICAgICAgICAgICBi
bG9jay0+bGF5ZXIoKS0+dXBkYXRlU2Nyb2xsSW5mb0FmdGVyTGF5b3V0KCk7CiAgICAgICAgICAg
ICB9CiAgICAgICAgIH0KLSAgICAgICAgZGVsZXRlIGdEZWxheWVkVXBkYXRlU2Nyb2xsSW5mb1Nl
dDsKLSAgICAgICAgZ0RlbGF5ZWRVcGRhdGVTY3JvbGxJbmZvU2V0ID0gMDsKLSAgICAgICAgQVNT
RVJUKCFnRGVsYXlVcGRhdGVTY3JvbGxJbmZvKTsKICAgICB9CiB9CiAKZGlmZiAtLWdpdCBhL0xh
eW91dFRlc3RzL0NoYW5nZUxvZyBiL0xheW91dFRlc3RzL0NoYW5nZUxvZwppbmRleCBlZmIyNmMz
ZTY4Y2VjNGI4ZDZkOTE2ZTMyNzFhZTZiMmExYzNmMzY4Li40MDQyMzM0ZWM0NTQ1ZjAwN2Q3ZGQ2
YjUwN2FjZWNhZjg0ODNiNzBkIDEwMDY0NAotLS0gYS9MYXlvdXRUZXN0cy9DaGFuZ2VMb2cKKysr
IGIvTGF5b3V0VGVzdHMvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTUgQEAKKzIwMTMtMDEtMDcgIFNo
ZXJpZmYgQm90ICA8d2Via2l0LnJldmlldy5ib3RAZ21haWwuY29tPgorCisgICAgICAgIFVucmV2
aWV3ZWQsIHJvbGxpbmcgb3V0IHIxMzc2MzIuCisgICAgICAgIGh0dHA6Ly90cmFjLndlYmtpdC5v
cmcvY2hhbmdlc2V0LzEzNzYzMgorICAgICAgICBodHRwczovL2J1Z3Mud2Via2l0Lm9yZy9zaG93
X2J1Zy5jZ2k/aWQ9MTA2MjM3CisKKyAgICAgICAgQ2F1c2VkIG1ham9yIHNlY3VyaXR5IHJlZ3Jl
c3Npb25zIG9uIENsdXN0ZXJGdXp6IChSZXF1ZXN0ZWQgYnkKKyAgICAgICAgaW5mZXJuby1zZWMg
b24gI3dlYmtpdCkuCisKKyAgICAgICAgKiBtYXRobWwvbW8tc3RyZXRjaC1jcmFzaC1leHBlY3Rl
ZC50eHQ6IFJlbW92ZWQuCisgICAgICAgICogbWF0aG1sL21vLXN0cmV0Y2gtY3Jhc2guaHRtbDog
UmVtb3ZlZC4KKwogMjAxMy0wMS0wNyAgTWljaGFlbCBQcnVldHQgIDxtaWNoYWVsQDY4ay5vcmc+
CiAKICAgICAgICAgW0pTQ10gQ29weSBub24taW5kZXggcHJvcGVydGllcyBvZiBhcnJheXMgaW4g
U2VyaWFsaXplZFNjcmlwdFZhbHVlCmRpZmYgLS1naXQgYS9MYXlvdXRUZXN0cy9tYXRobWwvbW8t
c3RyZXRjaC1jcmFzaC1leHBlY3RlZC50eHQgYi9MYXlvdXRUZXN0cy9tYXRobWwvbW8tc3RyZXRj
aC1jcmFzaC1leHBlY3RlZC50eHQKZGVsZXRlZCBmaWxlIG1vZGUgMTAwNjQ0CmluZGV4IDAxNjNh
YmM5ZTRhYWE4MGU3NThiYWU3NTIxOWY0M2ZhNTVjZWExNzcuLjAwMDAwMDAwMDAwMDAwMDAwMDAw
MDAwMDAwMDAwMDAwMDAwMDAwMDAKLS0tIGEvTGF5b3V0VGVzdHMvbWF0aG1sL21vLXN0cmV0Y2gt
Y3Jhc2gtZXhwZWN0ZWQudHh0CisrKyAvZGV2L251bGwKQEAgLTEsMiArMCwwIEBACi1UaGlzIHRl
c3QgcGFzc2VzIGlmIGl0IGRvZXMgbm90IGNyYXNoLgotCmRpZmYgLS1naXQgYS9MYXlvdXRUZXN0
cy9tYXRobWwvbW8tc3RyZXRjaC1jcmFzaC5odG1sIGIvTGF5b3V0VGVzdHMvbWF0aG1sL21vLXN0
cmV0Y2gtY3Jhc2guaHRtbApkZWxldGVkIGZpbGUgbW9kZSAxMDA2NDQKaW5kZXggOGM2NDQ2ZWY3
YmE4YzQ5ODY5MWFkZmE2NGE2YjU1ODYxMDBhODI3ZC4uMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAw
MDAwMDAwMDAwMDAwMDAwMAotLS0gYS9MYXlvdXRUZXN0cy9tYXRobWwvbW8tc3RyZXRjaC1jcmFz
aC5odG1sCisrKyAvZGV2L251bGwKQEAgLTEsMzAgKzAsMCBAQAotPCFET0NUWVBFIGh0bWw+Ci08
cSBpZD1xdW90ZT48L3E+Ci08ZGQgaWQ9ZGQ+Ci08Ym9keSBpZD1ib2R5PgotICAgIDxzdHlsZT4K
LSAgICAgICAgZGQsIHEsIG1mZW5jZWQsIGRpdiB7Ci0gICAgICAgICAgICB3aWR0aDogN3B4Owot
ICAgICAgICAgICAgb3ZlcmZsb3cteTogYXV0bzsKLSAgICAgICAgICAgIHBhZGRpbmctbGVmdDog
MTAwJTsKLSAgICAgICAgfQotICAgIDwvc3R5bGU+Ci0gICAgPHNjcmlwdD4KLSAgICAgICAgaWYg
KHdpbmRvdy50ZXN0UnVubmVyKQotICAgICAgICAgICAgdGVzdFJ1bm5lci5kdW1wQXNUZXh0KCk7
Ci0KLSAgICAgICAgYm9keS5jb250ZW50RWRpdGFibGUgPSAidHJ1ZSI7Ci0gICAgICAgIGZ1bmN0
aW9uIGNyYXNoKCkgewotICAgICAgICAgICAgbWZlbmNlZCA9IGRvY3VtZW50LmNyZWF0ZUVsZW1l
bnROUygiaHR0cDovL3d3dy53My5vcmcvMTk5OC9NYXRoL01hdGhNTCIsICJtZmVuY2VkIik7Ci0g
ICAgICAgICAgICBkaXYgPSBkb2N1bWVudC5jcmVhdGVFbGVtZW50KCJkaXYiKTsKLSAgICAgICAg
ICAgIG1mZW5jZWQuYXBwZW5kQ2hpbGQoZGl2KTsKLSAgICAgICAgICAgIGRkLmFwcGVuZENoaWxk
KG1mZW5jZWQpOwotICAgICAgICAgICAgYm9keS5zdHlsZS5kaXNwbGF5ID0gIi13ZWJraXQtZmxl
eCI7Ci0gICAgICAgICAgICBkaXYuYXBwZW5kQ2hpbGQocXVvdGUpOwotICAgICAgICB9Ci0gICAg
ICAgIHdpbmRvdy5hZGRFdmVudExpc3RlbmVyKCJsb2FkIiwgY3Jhc2gsIGZhbHNlKTsKLSAgICA8
L3NjcmlwdD4KLQotVGhpcyB0ZXN0IHBhc3NlcyBpZiBpdCBkb2VzIG5vdCBjcmFzaC4KLTwvYm9k
eT4KLTwvZGQ+Cg==
</data>

          </attachment>
      

    </bug>

</bugzilla>