New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 592838 link

Starred by 0 users

Issue metadata

Status: Fixed
Owner:
OOO until NaN
Closed: Apr 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in blink::Document::updateLayoutTreeIgnorePendingStylesheets

Project Member Reported by ClusterFuzz, Mar 8 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6486850098692096

Fuzzer: bj_broddelwerk
Job Type: linux_lsan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x000000000530
Crash State:
  blink::Document::updateLayoutTreeIgnorePendingStylesheets
  blink::Document::updateLayoutIgnorePendingStylesheets
  blink::TextIteratorAlgorithm<blink::EditingAlgorithm<blink::NodeTraversal> >::ra
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=209699:209703

Minimized Testcase (1.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95zrBv6pejD-h2NnlW4mdz73wsZ8-li16HYA_zPzziYQBEAeGYuG6s-ZP6EdXYtw_8wtqv_fXVwRRiZT-tg-s_mnf60Gd0ZMjCZ7Stu7eEBfg0rgl-ogi75-PNYZ_vrDsIyzb_BHF_R42DGoUn-PfdiTxQbUA

Filer: pucchakayala

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Labels: M-49 findit-for-crash Te-Logged
Owner: dglazkov@chromium.org
Status: Assigned (was: Available)
Suspected CLs	No CL in the regression range changes the crashed files. The result is the blame information.

Author: peria
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/270473a30a1cabe4bc684391557494f2188b616c
Time: Sat Nov 21 01:44:21 2015
The CL last changed line 824 of file Handle.h, which is stack frame 0.

Author: peria
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/270473a30a1cabe4bc684391557494f2188b616c
Time: Sat Nov 21 01:44:21 2015
The CL last changed line 380 of file Document.h, which is stack frame 1.

Author: rune@opera.com
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/192cf55fa442b0f947d52f7343a76565c4622273
Time: Wed Mar 04 19:57:51 2015
The CL last changed line 2031 of file Document.cpp, which is stack frame 2.

Author: tkent
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/15acc9dd530608bc5bef752dd6aacee07c7c8377
Time: Tue Feb 02 23:14:19 2016
The CL last changed line 2057 of file Document.cpp, which is stack frame 3.

Author: dglazkov
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/3576860f06d835f699521bccbb134b65d7326dca
Time: Sat Mar 05 00:19:50 2016
The CL last changed line 1097 of file TextIterator.cpp, which is stack frame 4.

Author: sigbjornf@opera.com
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/9bc725c0c136c2749ba5caff77fa649908c10f5e
Time: Fri Sep 11 08:07:06 2015
The CL last changed line 206 of file TextCheckingHelper.cpp, which is stack frame 5.

Author: sigbjornf@opera.com
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/0606d4d04b9ffe1a9d5e47a387e0fe5ea5f83376
Time: Thu Sep 10 13:06:12 2015
The CL last changed line 73 of file TextCheckingHelper.h, which is stack frame 6.

Suspected Component: chromium-blink
Suspected Cr- Label: Cr-Blink-DOM
Totally mine.
Reverted the offending change in https://crrev.com/3576860f06d835f699521bccbb134b65d7326dca
Status: Fixed (was: Assigned)
Project Member

Comment 5 by ClusterFuzz, Mar 12 2016

ClusterFuzz has detected this issue as fixed in range 380105:380830.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6486850098692096

Fuzzer: bj_broddelwerk
Job Type: linux_lsan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x000000000530
Crash State:
  blink::Document::updateLayoutTreeIgnorePendingStylesheets
  blink::Document::updateLayoutIgnorePendingStylesheets
  blink::TextIteratorAlgorithm<blink::EditingAlgorithm<blink::NodeTraversal> >::ra
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=209699:209703
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=380105:380830

Minimized Testcase (1.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95zrBv6pejD-h2NnlW4mdz73wsZ8-li16HYA_zPzziYQBEAeGYuG6s-ZP6EdXYtw_8wtqv_fXVwRRiZT-tg-s_mnf60Gd0ZMjCZ7Stu7eEBfg0rgl-ogi75-PNYZ_vrDsIyzb_BHF_R42DGoUn-PfdiTxQbUA

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Status: Assigned (was: Fixed)
Clusterfuzz is complaining in M49 & M50 do we need to revert the patch ?
Project Member

Comment 7 by ClusterFuzz, Mar 15 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6395815588790272

Fuzzer: bj_broddelwerk
Job Type: linux_lsan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x000000000530
Crash State:
  blink::Document::updateLayoutTreeIgnorePendingStylesheets
  blink::Document::updateLayoutIgnorePendingStylesheets
  blink::TextIteratorAlgorithm<blink::EditingAlgorithm<blink::NodeTraversal> >::Te
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=209699:209703

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv96eTobKTxx4rn5f4Eh5D_nfLOvzUONIOSI5rmdP3-KMULHzlOClt35U6Ynu9VFmaowRZuhLB6caLqytzTaArAW-BwnuHirEamjklRz-MGUSperRA3mGdh_TH_Vn2XHPnLG6CCFNkGjMZMtCbpiSkKr9li7uqchGzhjYAMM6u-3C1ivBzuc


Filer: ligimole

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
It would be weird if it was in 49. Are you sure it's the same issue? I already reverted the patch.
Components: Blink
Labels: -cr-blink
Remove legacy label cr-blink
Components: -Blink Blink>Layout
Status: Fixed (was: Assigned)
Hearing no feedback, closing.
Project Member

Comment 12 by ClusterFuzz, Apr 12 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6395815588790272

Fuzzer: bj_broddelwerk
Job Type: linux_lsan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x000000000530
Crash State:
  blink::Document::updateLayoutTreeIgnorePendingStylesheets
  blink::Document::updateLayoutIgnorePendingStylesheets
  blink::TextIteratorAlgorithm<blink::EditingAlgorithm<blink::NodeTraversal> >::Te
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=209699:209703

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv96eTobKTxx4rn5f4Eh5D_nfLOvzUONIOSI5rmdP3-KMULHzlOClt35U6Ynu9VFmaowRZuhLB6caLqytzTaArAW-BwnuHirEamjklRz-MGUSperRA3mGdh_TH_Vn2XHPnLG6CCFNkGjMZMtCbpiSkKr9li7uqchGzhjYAMM6u-3C1ivBzuc


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 13 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment