New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 595593 link

Starred by 0 users

Issue metadata

Status: Fixed
Owner:
NOT IN USE
Closed: Mar 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

ASSERTION FAILED: logicalBottom >= logicalTop

Project Member Reported by ClusterFuzz, Mar 17 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6728465161650176

Fuzzer: inferno_twister
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  ASSERTION FAILED: logicalBottom >= logicalTop
  blink::MultiColumnFragmentainerGroup::flowThreadPortionRectAt
  blink::MultiColumnFragmentainerGroup::flowThreadTranslationAtOffset
  

Minimized Testcase (0.11 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv95kLuh4HbpFxGmEjLYXYkcXyuUl_ILi3MwTPM_xNPk1Ujd2UIzGjGLKSR1lR7_hcuPpWpLgcx1ORVS6wPkQ1ADvj-D2KvRS4zMA97k8MvYTEz0bIXNWLaWDR-xT-YblgxU_oRYUNQCkSkiZjLpM4jSyZOkqUg
    }<div><div>
<style>
* { animation-name: cfpulse82; column-count: 37; outline: 61779px auto rgb(22, 79, 17);


Filer: ajha

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 

Comment 1 by ajha@chromium.org, Mar 17 2016

Cc: dsinclair@chromium.org
Components: Blink>Layout
Labels: -Cr-Blink findit-for-crash Te-Logged
Owner: msten...@opera.com
Status: Assigned (was: Available)
Suspected CLs	Regression information is not available. The result is the blame information.

Author: mstensho@opera.com
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/112f7d91b872201c590ee634c675bef7bf46c554
Time: Thu Jun 18 20:05:00 2015
The CL last changed line 396 of file MultiColumnFragmentainerGroup.cpp, which is stack frame 0.

Author: mstensho@opera.com
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/de44e7052d58771465b702142273af7faf20992d
Time: Wed Feb 11 12:16:26 2015
The CL last changed line 105 of file MultiColumnFragmentainerGroup.cpp, which is stack frame 1.

Author: mstensho@opera.com
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/d284f20c75a71030a6ff38c95a84d837c9a0a60b
Time: Thu Jun 18 17:04:01 2015
The CL last changed line 289 of file LayoutMultiColumnSet.cpp, which is stack frame 2.

Author: mstensho@opera.com
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/01844c28b8e107bae59e93ae5ddaeb479b059bb4
Time: Mon Aug 17 10:12:13 2015
The CL last changed line 333 of file LayoutMultiColumnFlowThread.cpp, which is stack frame 3.

Author: mstensho
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/562a7409200d3bffd2e1270e227e36d87724a07c
Time: Wed Dec 09 00:22:43 2015
The CL last changed line 116 of file MultiColumnFragmentainerGroup.cpp, which is stack frame 4.

Author: mstensho@opera.com
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/d284f20c75a71030a6ff38c95a84d837c9a0a60b
Time: Thu Jun 18 17:04:01 2015
The CL last changed line 289 of file LayoutMultiColumnSet.cpp, which is stack frame 5.

Author: mstensho@opera.com
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/01844c28b8e107bae59e93ae5ddaeb479b059bb4
Time: Mon Aug 17 10:12:13 2015
The CL last changed line 333 of file LayoutMultiColumnFlowThread.cpp, which is stack frame 6.

Suspected Component: chromium
Suspected Cr- Label: Cr-Blink-Layout

=====================================================

Assigning to  mstensho@ as all the Blame information point to changes by him.

Cc'ing dsinclair@ as well in case the minimized test case isn't accessible to mstensho@.

Thank you!
Project Member

Comment 2 by ClusterFuzz, Mar 23 2016

ClusterFuzz has detected this issue as fixed in range 382185:382588.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6728465161650176

Fuzzer: inferno_twister
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  ASSERTION FAILED: logicalBottom >= logicalTop
  blink::MultiColumnFragmentainerGroup::flowThreadPortionRectAt
  blink::MultiColumnFragmentainerGroup::flowThreadTranslationAtOffset
  
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=382185:382588

Minimized Testcase (0.11 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv95kLuh4HbpFxGmEjLYXYkcXyuUl_ILi3MwTPM_xNPk1Ujd2UIzGjGLKSR1lR7_hcuPpWpLgcx1ORVS6wPkQ1ADvj-D2KvRS4zMA97k8MvYTEz0bIXNWLaWDR-xT-YblgxU_oRYUNQCkSkiZjLpM4jSyZOkqUg
    }<div><div>
<style>
* { animation-name: cfpulse82; column-count: 37; outline: 61779px auto rgb(22, 79, 17);


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Comment 3 by ajha@chromium.org, Mar 23 2016

Status: Fixed (was: Assigned)
Marking this Fixed as per C#2.
Project Member

Comment 4 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment