Issue metadata
Sign in to add a comment
|
ASSERTION FAILED: Cannot rewind document lifecycle from InLayoutSubtreeChange to |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5719999458574336 Fuzzer: mbarbella_js_mutation_layout Job Type: linux_debug_content_shell_drt Platform Id: linux Crash Type: ASSERT Crash Address: Crash State: ASSERTION FAILED: Cannot rewind document lifecycle from InLayoutSubtreeChange to blink::DocumentLifecycle::ensureStateAtMost blink::FrameView::scheduleRelayout Minimized Testcase (0.20 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv961HzXnNmTEGu-im39TbFImT5y4sAeHGvXg17RJUBHmLW60nzCwXCY3e8w0jH-RXjDparMibcOtbSjXpatwsrfh2JAMbahpaMq6XZEnCKdpg9JJTkMMSfGVwz8lqkyAbe8D65H7J65qBOtrpXu_jaZqEaJ0hQ <body onload="__f_0();" style="-webkit-column-count:3; display:list-item;"> <script> document.designMode='on'; document.execCommand('selectall'); document.designMode= 'off'; document.execCommand(); </script> Filer: ajha See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Mar 14 2016
Please read CL descriptions when assigning bugs via blame. pdr@ maybe you can have a look?
,
Mar 15 2016
There's a nice minimial testcase for this one (attached). Leaving this unassigned but available for the paint team.
,
Mar 15 2016
I'll look a bit more at this, but it appears to be a layout but not paint, right?
,
Mar 17 2016
,
Mar 18 2016
Remove legacy label cr-blink
,
Mar 18 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/b1c6edeac6287b6ffe50cac44956b72f29bb76f5 commit b1c6edeac6287b6ffe50cac44956b72f29bb76f5 Author: chrishtr <chrishtr@chromium.org> Date: Fri Mar 18 17:18:04 2016 Remove lifecycle rewinding in FrameView::scheduleRelayout It was added in https://codereview.chromium.org/232013002 to find extra lifecycle violations. However, right now it is used in various cases to schedule relayout during layout because of change of containing block chain. This triggers the assert incorrectly (or layout should fix this, but it is considered ok for now). BUG= 594489 Review URL: https://codereview.chromium.org/1807363002 Cr-Commit-Position: refs/heads/master@{#381997} [modify] https://crrev.com/b1c6edeac6287b6ffe50cac44956b72f29bb76f5/third_party/WebKit/Source/core/frame/FrameView.cpp [modify] https://crrev.com/b1c6edeac6287b6ffe50cac44956b72f29bb76f5/third_party/WebKit/Source/web/tests/FrameThrottlingTest.cpp
,
Mar 18 2016
,
Mar 19 2016
ClusterFuzz has detected this issue as fixed in range 381909:382014. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5719999458574336 Fuzzer: mbarbella_js_mutation_layout Job Type: linux_debug_content_shell_drt Platform Id: linux Crash Type: ASSERT Crash Address: Crash State: ASSERTION FAILED: Cannot rewind document lifecycle from InLayoutSubtreeChange to blink::DocumentLifecycle::ensureStateAtMost blink::FrameView::scheduleRelayout Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=381909:382014 Minimized Testcase (0.20 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv961HzXnNmTEGu-im39TbFImT5y4sAeHGvXg17RJUBHmLW60nzCwXCY3e8w0jH-RXjDparMibcOtbSjXpatwsrfh2JAMbahpaMq6XZEnCKdpg9JJTkMMSfGVwz8lqkyAbe8D65H7J65qBOtrpXu_jaZqEaJ0hQ <body onload="__f_0();" style="-webkit-column-count:3; display:list-item;"> <script> document.designMode='on'; document.execCommand('selectall'); document.designMode= 'off'; document.execCommand(); </script> See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by ajha@chromium.org
, Mar 14 2016Owner: danakj@chromium.org
Status: Assigned (was: Available)