Files
sousa-gecko/testing/web-platform/tests/css/css-variables/missing-closing-nested-fallback-crash.html
T
Emilio Cobos Álvarez cdebb24a4e Bug 2013337 - Fix missing-closing-characters checks in custom property parsing. r=firefox-style-system-reviewers,dshin
What is going on in this page is:

 * We have two nested references + fallback, both with missing closing
   parens.
 * But the value actually ends with a closing paren, the rgb() function.

So we fail to detect that the closing parens are missing, and we mess up
the indices during substitution because we rely on the fallback end
being the end of the var() reference minus 1.

Properly tests for it by checking the block end against the
outside-of-the-block start. If they're the same there was no closing
paren. We could extend cssparser with this information maybe but for now
this seems ok. UnquotedUrl I think we can leave as-is.

Add two tests, once with a would be successful substitution that we get
wrong right now, but this patch fixes, and the actually crashing test.

I'm a bit surprised that no fuzzer has found this before tbh...

Differential Revision: https://phabricator.services.mozilla.com/D281506
2026-02-02 20:08:05 +00:00

9 lines
572 B
HTML

<!doctype html>
<title>Variable substitution with missing closing parenthesis</title>
<link rel="help" href="https://bugzilla.mozilla.org/show_bug.cgi?id=2013337">
<link rel="author" title="Emilio Cobos Álvarez" href="mailto:emilio@crisal.io">
<link rel="author" title="Mozilla" href="https://mozilla.com">
<div
style="box-shadow:0px 0px 3px 1px var(--token-62be83f1-0097-4872-b224-94c7b2aa11d6, nullpx nullpx nullpx nullpx rgb(245, 245, 245), 0px 0px 4px 2px var(--token-63fea906-5b5e-4ed0-9785-37e4c202cb5f, nullpx nullpx nullpx undefinedpx rgb(1, 255, 148)"
></div>