insertPargraphSeparator commands hits assertion when inserting into STYLE element |
|||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5056377675841536 Fuzzer: inferno_layout_test_unmodified Job Type: linux_debug_content_shell_drt Platform Id: linux Crash Type: ASSERT Crash Address: Crash State: ASSERTION FAILED: endingSelection().isCaretOrRange() blink::CompositeEditCommand::moveParagraphs blink::CompositeEditCommand::moveParagraph Minimized Testcase (1.85 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95pTuZepKU-VcWIpNY1lISSnEMrBgUJqUaDZCj0CLKTZHHC5LVnzKuvEzDFk6XK9l-b7vLokQZ2WNWrksXZtAEFWUvh9Apy7JxgwnjXMfRGc_wusb6oVz1iU3fp6OM20Ol1UgeV3F_RLGCd9hLy96mXUiMiGg Filer: ajha See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Mar 18 2016
,
Mar 22 2016
insertPargraphSeparator command attempts to insert STYLE element as paragraph separator, since insertion position is enclosed by STYLE element with "display:block"
ASSERTION FAILED: endingSelection().isCaretOrRange()
m_enidngSeleciton is null.
DOM tree before insertPargraphSeparator command:
#document 00000192A8002578 (editable)
HTML 00000192A8003180 (editable) (focused)
HEAD 00000192A80031E8 (editable)
#text 00000192A8003318 "\n"
STYLE 00000192A8003368 (editable)
#text 00000192A80033F8 "\n"
META 00000192A8003498 (editable)
SE #text 00000192A8003568 "*{-webkit-animation-play-state:paused;display:block;"
#text 00000192A8003448 "\n"
start: offset, offset:0
end: offset, offset:0
,
Jul 6 2016
ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5056377675841536 Fuzzer: inferno_layout_test_unmodified Job Type: linux_debug_content_shell_drt Platform Id: linux Crash Type: ASSERT Crash Address: Crash State: endingSelection().isCaretOrRange() blink::CompositeEditCommand::moveParagraphs blink::CompositeEditCommand::moveParagraph Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=275840:275883 Minimized Testcase (3.96 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94aBrrXLyA1EY5wJ5tvce_Xhqj1O96v62wPbq_ThAmEH13lOI3bt_dbsBSBvOmyxdt74nZtA1ES6Ws_t8c8FgFVM70AUxBfpKmjHpZWGQKl7mwELA2AeDafNgdOPzsKLet6JW3RiNNAnymQF32oT8rx_bpG9w?testcase_id=5056377675841536 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jul 7 2016
Mark WontFix according to #c4 and I could not reproduce with ToT.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||
►
Sign in to add a comment |
|||||
Comment 1 by ajha@chromium.org
, Mar 18 2016Labels: findit-for-crash Te-Logged
Owner: tkent@chromium.org
Status: Assigned (was: Available)