<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>53536</bug_id>
          
          <creation_ts>2011-02-01 14:53:24 -0800</creation_ts>
          <short_desc>Overflow in WebKit2 argument decoder buffer checking</short_desc>
          <delta_ts>2011-02-02 09:59:31 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebKit2</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Darin Adler">darin</reporter>
          <assigned_to name="Darin Adler">darin</assigned_to>
          <cc>andersca</cc>
    
    <cc>commit-queue</cc>
    
    <cc>webkit.review.bot</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>343567</commentid>
    <comment_count>0</comment_count>
    <who name="Darin Adler">darin</who>
    <bug_when>2011-02-01 14:53:24 -0800</bug_when>
    <thetext>Fix overflow in WebKit2 argument decoder buffer checking</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>343569</commentid>
    <comment_count>1</comment_count>
      <attachid>80832</attachid>
    <who name="Darin Adler">darin</who>
    <bug_when>2011-02-01 14:56:29 -0800</bug_when>
    <thetext>Created attachment 80832
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>343676</commentid>
    <comment_count>2</comment_count>
      <attachid>80832</attachid>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2011-02-01 16:49:29 -0800</bug_when>
    <thetext>Comment on attachment 80832
Patch

Rejecting attachment 80832 from commit-queue.

Failed to run &quot;[&apos;./Tools/Scripts/webkit-patch&apos;, &apos;--status-host=queues.webkit.org&apos;, &apos;--bot-id=cr-jail-4&apos;, &apos;build&apos;...&quot; exit_code: 2

Last 500 characters of output:
rip-debug-symbols -resolve-src-symlinks /mnt/git/webkit-commit-queue/WebKitBuild/Debug/WebProcess.app /mnt/git/webkit-commit-queue/WebKitBuild/Debug/WebKit2.framework

** BUILD FAILED **


The following build commands failed:
WebKit2:
	CompileC /mnt/git/webkit-commit-queue/WebKitBuild/WebKit2.build/Debug/WebKit2.build/Objects-normal/x86_64/ArgumentDecoder.o /mnt/git/webkit-commit-queue/Source/WebKit2/Platform/CoreIPC/ArgumentDecoder.cpp normal x86_64 c++ com.apple.compilers.gcc.4_2
(1 failure)


Full output: http://queues.webkit.org/results/7687341</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>343789</commentid>
    <comment_count>3</comment_count>
    <who name="WebKit Review Bot">webkit.review.bot</who>
    <bug_when>2011-02-01 19:47:33 -0800</bug_when>
    <thetext>Attachment 80832 did not build on mac:
Build output: http://queues.webkit.org/results/7681951</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>344018</commentid>
    <comment_count>4</comment_count>
    <who name="Darin Adler">darin</who>
    <bug_when>2011-02-02 09:59:31 -0800</bug_when>
    <thetext>Committed r77378: &lt;http://trac.webkit.org/changeset/77378&gt;</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>80832</attachid>
            <date>2011-02-01 14:56:29 -0800</date>
            <delta_ts>2011-02-01 16:49:29 -0800</delta_ts>
            <desc>Patch</desc>
            <filename>bug-53536-20110201145627.patch</filename>
            <type>text/plain</type>
            <size>2301</size>
            <attacher name="Darin Adler">darin</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9XZWJLaXQyL0NoYW5nZUxvZwo9PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBTb3VyY2UvV2Vi
S2l0Mi9DaGFuZ2VMb2cJKHJldmlzaW9uIDc3MzE2KQorKysgU291cmNlL1dlYktpdDIvQ2hhbmdl
TG9nCSh3b3JraW5nIGNvcHkpCkBAIC0xLDMgKzEsMTcgQEAKKzIwMTEtMDItMDEgIERhcmluIEFk
bGVyICA8ZGFyaW5AYXBwbGUuY29tPgorCisgICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09Q
UyEpLgorCisgICAgICAgIE92ZXJmbG93IGluIFdlYktpdDIgYXJndW1lbnQgZGVjb2RlciBidWZm
ZXIgY2hlY2tpbmcKKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dp
P2lkPTUzNTM2CisKKyAgICAgICAgKiBQbGF0Zm9ybS9Db3JlSVBDL0FyZ3VtZW50RGVjb2Rlci5j
cHA6CisgICAgICAgIChDb3JlSVBDOjpyb3VuZFVwVG9BbGlnbm1lbnQpOiBUd2VhayBjb2RlIGEg
Yml0IGZvciBjbGFyaXR5IGFuZCB0byByZXBsYWNlCisgICAgICAgIEMgY2FzdHMgd2l0aCBDKysg
Y2FzdHMuCisgICAgICAgIChDb3JlSVBDOjpBcmd1bWVudERlY29kZXI6OmFsaWduQnVmZmVyUG9z
aXRpb24pOiBSZWFycmFuZ2UgYnVmZmVyIGNhbGN1bGF0aW9uCisgICAgICAgIHNvIHdlIGRvbid0
IGRvIGFueSBtYXRoIHdpdGggdGhlIHBhc3NlZC1pbiBzaXplLCBiZWNhdXNlIHRoYXQgY291bGQg
b3ZlcmZsb3cuCisgICAgICAgIChDb3JlSVBDOjpBcmd1bWVudERlY29kZXI6OmJ1ZmZlcklzTGFy
Z2VFbm91Z2hUb0NvbnRhaW4pOiBEaXR0by4KKwogMjAxMS0wMi0wMSAgQW5kZXJzIENhcmxzc29u
ICA8YW5kZXJzY2FAYXBwbGUuY29tPgogCiAgICAgICAgIFJldmlld2VkIGJ5IEFkYW0gUm9iZW4u
CkluZGV4OiBTb3VyY2UvV2ViS2l0Mi9QbGF0Zm9ybS9Db3JlSVBDL0FyZ3VtZW50RGVjb2Rlci5j
cHAKPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PQotLS0gU291cmNlL1dlYktpdDIvUGxhdGZvcm0vQ29yZUlQQy9Bcmd1bWVu
dERlY29kZXIuY3BwCShyZXZpc2lvbiA3NzMxMSkKKysrIFNvdXJjZS9XZWJLaXQyL1BsYXRmb3Jt
L0NvcmVJUEMvQXJndW1lbnREZWNvZGVyLmNwcAkod29ya2luZyBjb3B5KQpAQCAtNjksMTMgKzY5
LDE1IEBAIHZvaWQgQXJndW1lbnREZWNvZGVyOjppbml0aWFsaXplKGNvbnN0IHUKIAogc3RhdGlj
IGlubGluZSB1aW50OF90KiByb3VuZFVwVG9BbGlnbm1lbnQodWludDhfdCogcHRyLCB1bnNpZ25l
ZCBhbGlnbm1lbnQpCiB7Ci0gICAgcmV0dXJuICh1aW50OF90KikoKCh1aW50cHRyX3QpcHRyICsg
YWxpZ25tZW50IC0gMSkgJiB+KHVpbnRwdHJfdCkoYWxpZ25tZW50IC0gMSkpOworICAgIEFTU0VS
VChhbGlnbm1lbnQpOworICAgIHVpbnRwdHJfdCBhbGlnbm1lbnRNYXNrID0gYWxpZ25tZW50IC0g
MTsKKyAgICByZXR1cm4gcmVpbnRlcnByZXRfY2FzdDx1aW50OF90Kj4oKHJlaW50ZXJwcmV0X2Nh
c3Q8dWludHB0cl90PihwdHIpICsgYWxpZ25tZW50TWFzaykgJiB+YWxpZ25tZW50TWFzayk7CiB9
CiAKIGJvb2wgQXJndW1lbnREZWNvZGVyOjphbGlnbkJ1ZmZlclBvc2l0aW9uKHVuc2lnbmVkIGFs
aWdubWVudCwgc2l6ZV90IHNpemUpCiB7CiAgICAgdWludDhfdCogYnVmZmVyID0gcm91bmRVcFRv
QWxpZ25tZW50KG1fYnVmZmVyUG9zLCBhbGlnbm1lbnQpOwotICAgIGlmIChidWZmZXIgKyBzaXpl
ID4gbV9idWZmZXJFbmQpIHsKKyAgICBpZiAobV9idWZmZXJFbmQgLSBidWZmZXIgPCBzaXplKSB7
CiAgICAgICAgIC8vIFdlJ3ZlIHdhbGtlZCBvZmYgdGhlIGVuZCBvZiB0aGlzIGJ1ZmZlci4KICAg
ICAgICAgbWFya0ludmFsaWQoKTsKICAgICAgICAgcmV0dXJuIGZhbHNlOwpAQCAtODcsNyArODks
NyBAQCBib29sIEFyZ3VtZW50RGVjb2Rlcjo6YWxpZ25CdWZmZXJQb3NpdGlvCiAKIGJvb2wgQXJn
dW1lbnREZWNvZGVyOjpidWZmZXJJc0xhcmdlRW5vdWdoVG9Db250YWluKHVuc2lnbmVkIGFsaWdu
bWVudCwgc2l6ZV90IHNpemUpIGNvbnN0CiB7Ci0gICAgcmV0dXJuIHJvdW5kVXBUb0FsaWdubWVu
dChtX2J1ZmZlclBvcywgYWxpZ25tZW50KSArIHNpemUgPD0gbV9idWZmZXJFbmQ7CisgICAgcmV0
dXJuIG1fYnVmZmVyRW5kIC0gcm91bmRVcFRvQWxpZ25tZW50KG1fYnVmZmVyUG9zLCBhbGlnbm1l
bnQpID49IHNpemU7CiB9CiAKIGJvb2wgQXJndW1lbnREZWNvZGVyOjpkZWNvZGVCeXRlcyhWZWN0
b3I8dWludDhfdD4mIGJ1ZmZlcikK
</data>
<flag name="review"
          id="72335"
          type_id="1"
          status="+"
          setter="andersca"
    />
    <flag name="commit-queue"
          id="72336"
          type_id="3"
          status="-"
          setter="commit-queue"
    />
          </attachment>
      

    </bug>

</bugzilla>