New issue
Advanced search Search tips

Issue 594786 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Jul 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

ASSERTION FAILED: caretLayoutItem.isDescendantOf(caretPainterItem)

Project Member Reported by ClusterFuzz, Mar 14 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5669101149618176

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  ASSERTION FAILED: caretLayoutItem.isDescendantOf(caretPainterItem)
  blink::mapCaretRectToCaretPainter
  blink::CaretBase::updateCaretRect
  

Minimized Testcase (1.36 Kb): https://cluster-fuzz.appspot.com/download/AMIfv966WmYn3GyCsGO0tKirvYyUsqnmQTw_TTDV-1VfcdbTyYGm6CfRh96MW6mZytloXWb4P50m4qTzFvy7_CtZS40N0IqhQhMW1QBy1vGKOfeAdmKAa8R4XDcYidLYo2hsnuwZeUGWwybusXJV3IWZsiVtDbCl_A

Filer: pucchakayala

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Labels: findit-for-crash Te-Logged M-50
Owner: yoichio@chromium.org
Status: Assigned (was: Available)
Suspected CLs	Regression information is not available. The result is the blame information.

Author: pilgrim
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/870ba802072a399283538e789fbd986ebf149f4f
Time: Fri Feb 26 03:53:51 2016
The CL last changed line 76 of file CaretBase.cpp, which is stack frame 0.

Author: pilgrim
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/870ba802072a399283538e789fbd986ebf149f4f
Time: Fri Feb 26 03:53:51 2016
The CL last changed line 110 of file CaretBase.cpp, which is stack frame 1.

Author: yosin@chromium.org
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/4268a7ffa3e38bd13891de298f178b1a26193619
Time: Fri Jul 24 10:05:29 2015
The CL last changed line 117 of file CaretBase.cpp, which is stack frame 2.

Author: yoichio
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/188ceeb4e4096ce08af858619d5f07e550ad4d0d
Time: Fri Mar 04 01:54:53 2016
The CL last changed line 702 of file FrameSelection.cpp, which is stack frame 3.

Author: tkent@chromium.org
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/4598219713617cd1d7b4d45bab8ce4959ee5fa42
Time: Tue Sep 03 02:16:04 2013
The CL last changed line 2600 of file WebViewImpl.cpp, which is stack frame 4.

Author: cjhopman@chromium.org
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/7c8873e00bfd0d447c1e275f98f8617268af46cd
Time: Tue Feb 05 08:03:01 2013
The CL last changed line 1820 of file render_widget.cc, which is stack frame 5.

Author: kinaba@chromium.org
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/3f783369aa10fa323d79b6ec69afbd7035350fcd
Time: Fri Oct 21 22:40:50 2011
The CL last changed line 3076 of file render_view_impl.cc, which is stack frame 6.

Suspected Component: chromium
Suspected Cr- Label: Cr-Blink-Editing
Components: Blink
Labels: -cr-blink
Remove legacy label cr-blink
Components: -Blink Blink>Layout
Project Member

Comment 4 by ClusterFuzz, Jul 6 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5669101149618176

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  caretLayoutItem.isDescendantOf(caretPainterItem)
  blink::mapCaretRectToCaretPainter
  blink::CaretBase::updateCaretRect
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=297440:297710

Minimized Testcase (3.62 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96u1yz8IpmPLeTbQaydKtiMPkcbzlBbIO6Q5zoVbIhvs73gh8YoHUxYFv6z9qmewxDXcYfg_oIURidRUVUg3bnymQvEtjwQwmkNvkL97VXUdJr85258tcQ7QwTU8n0msmz54XQEJA2TaDs1a-VzTEawYidycQ?testcase_id=5669101149618176

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Comment 5 by e...@chromium.org, Jul 19 2016

Status: WontFix (was: Assigned)
Closing as per comment 4.
Project Member

Comment 6 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment