New issue
Advanced search Search tips

Issue 593606 link

Starred by 0 users

Issue metadata

Status: Fixed
Owner: ----
Closed: Dec 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

JusifyCenter command crashes with CSS property max-height with small value

Project Member Reported by ClusterFuzz, Mar 10 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5914994738200576

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  ASSERTION FAILED: node
  blink::CompositeEditCommand::isRemovableBlock
  blink::DeleteSelectionCommand::removeRedundantBlocks
  

Minimized Testcase (2.70 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96H4AIufun7FgsIvseRPlSUcyxswmGrP2R5W3gySIBXKDgQSSc6Huxvccbdj9-31-Ci4Sffg963m3lSjfZIKVz-n8CEy1diTzNjPym8UxdqM1VjGmwq8YhdtVetLYFTPYqGYdc6AjCDnHfiRL4d_ToRO-mEsw

Filer: nyerramilli

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: nyerramilli@chromium.org
Labels: M-49 findit-wrong Te-Logged
Owner: tkent@chromium.org
Status: Assigned (was: Available)
using codesearch seeing some changes to CompositeEditCommand in 
https://chromium.googlesource.com/chromium/src/+/8fa61a69304e774ec9e4c1e944a2fc151c02c0ab

tkent@, Could you please check the above issue & help us in finding an owner it its not yours.

Providing Findit information for internal purpose:
-----------------------------------------------------
Regression information is not available. The result is the blame information.

Author: ch.dumez@samsung.com
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/cb14ba27851dca0113b1f0eefcd26d04a4d0a6a2
Time: Fri Mar 14 21:37:55 2014
The CL last changed line 306 of file CompositeEditCommand.cpp, which is stack frame 0.

Author: enrica@apple.com
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/6ca16d9354965cb55343d9e28b1de1bc44725449
Time: Thu Dec 15 00:32:27 2011
The CL last changed line 816 of file DeleteSelectionCommand.cpp, which is stack frame 1.

Author: tkent
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/7f6bd2b6a8e6e4858afd1f1b23d768030a01af69
Time: Wed Feb 10 02:54:06 2016
The CL last changed line 913 of file DeleteSelectionCommand.cpp, which is stack frame 2.

Author: tkent
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/141f0e9340ec887e341ba89a712c6539205a8292
Time: Tue Feb 09 12:09:23 2016
The CL last changed line 255 of file CompositeEditCommand.cpp, which is stack frame 3.

Author: tkent
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/7f6bd2b6a8e6e4858afd1f1b23d768030a01af69
Time: Wed Feb 10 02:54:06 2016
The CL last changed line 621 of file CompositeEditCommand.cpp, which is stack frame 4.

Author: tkent
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/2df3e5c169263f58f3da42ef4d2b518a362f2df5
Time: Wed Feb 10 05:12:58 2016
The CL last changed line 1308 of file CompositeEditCommand.cpp, which is stack frame 5.

Author: tkent
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/f71cdf416971d6c7dc7ffeee3077310a2bd02372
Time: Fri Feb 12 05:51:04 2016
The CL last changed line 1029 of file CompositeEditCommand.cpp, which is stack frame 6.

Suspected Component: chromium
Suspected Cr- Label: Cr-Blink-Editing

Comment 2 by tkent@chromium.org, Mar 10 2016

Components: Blink>Editing
Labels: -M-49 -Cr-Blink-Compositing
Route to editing triage.

nyerramilli@, 'CompositeEditCommand' is not Blink>Compositing. #1 correctly says "Suspected Cr- Label: Cr-Blink-Editing"


Comment 3 by tkent@chromium.org, Mar 10 2016

Owner: ----
Status: Untriaged (was: Assigned)

Comment 4 by yosin@chromium.org, Mar 10 2016

Labels: -Pri-1 Pri-2
Status: Available (was: Untriaged)
Summary: JusifyCenter command crashes with CSS property max-height with small value (was: ASSERTION FAILED: node)
Lower to Pri-2, since usage of JustyCenter is low.
Project Member

Comment 5 by ClusterFuzz, May 14 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5914994738200576

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  ASSERTION FAILED: node
  blink::CompositeEditCommand::isRemovableBlock
  blink::DeleteSelectionCommand::removeRedundantBlocks
  

Minimized Testcase (2.70 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96H4AIufun7FgsIvseRPlSUcyxswmGrP2R5W3gySIBXKDgQSSc6Huxvccbdj9-31-Ci4Sffg963m3lSjfZIKVz-n8CEy1diTzNjPym8UxdqM1VjGmwq8YhdtVetLYFTPYqGYdc6AjCDnHfiRL4d_ToRO-mEsw

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 6 by ClusterFuzz, Jun 9 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6515603976486912

Fuzzer: inferno_layout_test_unmodified
Job Type: windows_syzyasan_content_shell
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 0x0000000b
Crash State:
  blink::CompositeEditCommand::isRemovableBlock
  blink::DeleteSelectionCommand::removeRedundantBlocks
  blink::DeleteSelectionCommand::doApply
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=398496:398502

Minimized Testcase (2.71 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95ADwouD1N7WRkypKLOE4l7muBhXBj07q514AqfmQL2jciotO9saiZzD5D0V7JZqISfd2IgLUZUYnGGVX0YEcwenD_gzQIiDo9qq99GmoTMBdasIgu8wVCDWmgdqWocE37m85sMIcY1GNArGKtqsR97AQJwpA

Filer: ashejole

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Project Member

Comment 7 by ClusterFuzz, Jun 12 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6515603976486912

Fuzzer: inferno_layout_test_unmodified
Job Type: windows_syzyasan_content_shell
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 0x0000000b
Crash State:
  blink::CompositeEditCommand::isRemovableBlock
  blink::DeleteSelectionCommand::removeRedundantBlocks
  blink::DeleteSelectionCommand::doApply
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=398496:398502

Minimized Testcase (2.71 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95ADwouD1N7WRkypKLOE4l7muBhXBj07q514AqfmQL2jciotO9saiZzD5D0V7JZqISfd2IgLUZUYnGGVX0YEcwenD_gzQIiDo9qq99GmoTMBdasIgu8wVCDWmgdqWocE37m85sMIcY1GNArGKtqsR97AQJwpA

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 8 by ClusterFuzz, Jun 13 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6137214086152192

Fuzzer: inferno_layout_test_unmodified
Job Type: windows_syzyasan_content_shell
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 0x0000000b
Crash State:
  blink::CompositeEditCommand::isRemovableBlock
  blink::DeleteSelectionCommand::removeRedundantBlocks
  blink::DeleteSelectionCommand::doApply
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=399164:399271

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv94BVUlFV_JOIMbHpfcixQd5FAknYfBfabNKRbrhokhUT7td0nsB7SO4vKfi7NvA6LfDmdhtg3QDkLfhpV82CAR2xa-ATjuMGImnYLry_AVxYs4wmzuZAIzBMa2aZaH9cXloYYC85a92xj_ljCoUHuprsc7rpg


Filer: brajkumar

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Project Member

Comment 9 by ClusterFuzz, Jun 18 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6137214086152192

Fuzzer: inferno_layout_test_unmodified
Job Type: windows_syzyasan_content_shell
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 0x0000000b
Crash State:
  blink::CompositeEditCommand::isRemovableBlock
  blink::DeleteSelectionCommand::removeRedundantBlocks
  blink::DeleteSelectionCommand::doApply
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=399164:399271

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv94BVUlFV_JOIMbHpfcixQd5FAknYfBfabNKRbrhokhUT7td0nsB7SO4vKfi7NvA6LfDmdhtg3QDkLfhpV82CAR2xa-ATjuMGImnYLry_AVxYs4wmzuZAIzBMa2aZaH9cXloYYC85a92xj_ljCoUHuprsc7rpg?testcase_id=6137214086152192


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 10 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Changing the status to Fixed as per Comment# 9, as Cluster Fuzz detected this issue to be fixed.
Thanks.
Status: Fixed (was: Available)

Sign in to add a comment