New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 593254 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
NOT IN USE
Closed: Apr 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

ASSERTION FAILED: minSpaceShortage != LayoutUnit::max()

Project Member Reported by ClusterFuzz, Mar 9 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5155309506527232

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  ASSERTION FAILED: minSpaceShortage != LayoutUnit::max()
  blink::MultiColumnFragmentainerGroup::rebalanceColumnHeightIfNeeded
  blink::MultiColumnFragmentainerGroup::recalculateColumnHeight
  

Minimized Testcase (0.08 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv96mci-mAzSQKbK5X9C8m2STmkRfb35Ukhj2SBlfyL3yqdCu-7NFOeAmeuahInpmAEsyQHwrX3qonQVZAtOzdxXyAoe3C2mVmPYvbFARHCSxVdKdVvVp4w34PyB0DxGP2iV0CGs7ZIaho7KAEbB81GSrp9xTag
<style>
    html, body { 
    	-webkit-column-width: 200px; 
</style>
        }, 0);


Filer: nyerramilli

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: nyerramilli@chromium.org
Labels: M-49 findit-wrong Te-Logged
Owner: dgro...@chromium.org
Status: Assigned (was: Available)
Providing Findit information for internal purpose:

Suspected CLs	Regression information is not available. The result is the blame information.

Author: mstensho
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/ce77a26bc7b22cf511e91b336f40ae405712f66b
Time: Sat Oct 10 10:00:40 2015
The CL last changed line 351 of file MultiColumnFragmentainerGroup.cpp, which is stack frame 0.

Author: mstensho
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/3cfb1712dfae0983720f1cee06810a103484f271
Time: Mon Nov 23 10:13:55 2015
The CL last changed line 86 of file MultiColumnFragmentainerGroup.cpp, which is stack frame 1.

Author: mstensho
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/7829897fa89bec64fa0dbc45471d1fa784ead98d
Time: Tue Dec 01 20:55:52 2015
The CL last changed line 315 of file LayoutMultiColumnSet.cpp, which is stack frame 2.

Author: mstensho
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/5b549adb97c791f7e3362c529deecc702b3443d4
Time: Thu Jan 14 07:50:47 2016
The CL last changed line 346 of file LayoutMultiColumnSet.cpp, which is stack frame 3.

Author: mstensho@opera.com
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/bbdbf9ffa99ba94466aa14a698a7b0ccbf05eaff
Time: Mon Sep 07 09:07:52 2015
The CL last changed line 555 of file LayoutBlockFlow.cpp, which is stack frame 4.

Author: mstensho@opera.com
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/bbdbf9ffa99ba94466aa14a698a7b0ccbf05eaff
Time: Mon Sep 07 09:07:52 2015
The CL last changed line 580 of file LayoutBlockFlow.cpp, which is stack frame 5.

Author: sunil.ratnu@samsung.com
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/5c86cf307f860df1f1271f330a76c2d51f8abc34
Time: Thu Nov 27 13:13:01 2014
The CL last changed line 1047 of file LayoutBlockFlow.cpp, which is stack frame 6.

Suspected Component: chromium
Suspected Cr- Label: Cr-Blink-Layout

---------------------
using codesearch, seeing some changes to LayoutBlockFlow.cpp in https://chromium.googlesource.com/chromium/src/+/2fd8e4969be977a1b873473424b77cc889eef915

dgrogan@, Could you please check the above issue & help us in finding an owner it its not yours.
Owner: msten...@opera.com
mstensho knows multicol
Components: Blink>LayoutTests
Labels: -Cr-Blink-LayoutTests
Remove legacy label Cr-Blink-LayoutTests

Comment 4 by msten...@opera.com, Mar 31 2016

Cannot reproduce this.

Comment 5 by msten...@opera.com, Apr 8 2016

Status: WontFix (was: Assigned)
Still cannot reproduce this.
Project Member

Comment 6 by ClusterFuzz, Apr 19 2016

ClusterFuzz has detected this issue as fixed in range 388050:388121.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5155309506527232

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  ASSERTION FAILED: minSpaceShortage != LayoutUnit::max()
  blink::MultiColumnFragmentainerGroup::rebalanceColumnHeightIfNeeded
  blink::MultiColumnFragmentainerGroup::recalculateColumnHeight
  
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=388050:388121

Minimized Testcase (0.08 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv96mci-mAzSQKbK5X9C8m2STmkRfb35Ukhj2SBlfyL3yqdCu-7NFOeAmeuahInpmAEsyQHwrX3qonQVZAtOzdxXyAoe3C2mVmPYvbFARHCSxVdKdVvVp4w34PyB0DxGP2iV0CGs7ZIaho7KAEbB81GSrp9xTag
<style>
    html, body { 
    	-webkit-column-width: 200px; 
</style>
        }, 0);


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Comment 7 by sshru...@google.com, May 18 2016

Labels: Test-Layout
Project Member

Comment 8 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment