What is going on in this page is: * We have two nested references + fallback, both with missing closing parens. * But the value actually ends with a closing paren, the rgb() function. So we fail to detect that the closing parens are missing, and we mess up the indices during substitution because we rely on the fallback end being the end of the var() reference minus 1. Properly tests for it by checking the block end against the outside-of-the-block start. If they're the same there was no closing paren. We could extend cssparser with this information maybe but for now this seems ok. UnquotedUrl I think we can leave as-is. Add two tests, once with a would be successful substitution that we get wrong right now, but this patch fixes, and the actually crashing test. I'm a bit surprised that no fuzzer has found this before tbh... Differential Revision: https://phabricator.services.mozilla.com/D281506
9 lines
572 B
HTML
9 lines
572 B
HTML
<!doctype html>
|
|
<title>Variable substitution with missing closing parenthesis</title>
|
|
<link rel="help" href="https://bugzilla.mozilla.org/show_bug.cgi?id=2013337">
|
|
<link rel="author" title="Emilio Cobos Álvarez" href="mailto:emilio@crisal.io">
|
|
<link rel="author" title="Mozilla" href="https://mozilla.com">
|
|
<div
|
|
style="box-shadow:0px 0px 3px 1px var(--token-62be83f1-0097-4872-b224-94c7b2aa11d6, nullpx nullpx nullpx nullpx rgb(245, 245, 245), 0px 0px 4px 2px var(--token-63fea906-5b5e-4ed0-9785-37e4c202cb5f, nullpx nullpx nullpx undefinedpx rgb(1, 255, 148)"
|
|
></div>
|