New issue
Advanced search Search tips

Issue 596861 link

Starred by 0 users

Issue metadata

Status: Duplicate
Owner:
Closed: Mar 2016
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

ASSERTION FAILED: i < size()

Project Member Reported by ClusterFuzz, Mar 22 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4696095283740672

Fuzzer: inferno_twister
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  ASSERTION FAILED: i < size()
  blink::SVGTextMetricsCalculator::currentCharacterMetrics
  blink::measureTextLayoutObject
  

Minimized Testcase (180.31 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96MSDy2eNM7i5HCVuKQniwE4EhXq_gr1NdgXDF_SDpJdEvd7jN1u_8DJBiHdwrA9IBBK6kt510lPBNX2M3ISlTIIxxRTjfL3fuVXNYAbP6XyDEf678BL8JkZWYiyETIJ7fGyzHx1kAFaw23EtNNaPyDd9WaEMtY5l7W4h3lwdQAlOYC6AA

Additional requirements: Requires Gestures

Filer: ashejole

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Labels: -Pri-1 findit-wrong Te-Logged M-51 Pri-2
Owner: pdr@chromium.org
Status: Assigned (was: Available)
Suspected CLs	Regression information is not available. The result is the blame information.

Author: tkent
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/bee5120a945d2d5136c0ddf90f1bad618a96e5b3
Time: Wed Sep 30 07:59:25 2015
The CL last changed line 715 of file Vector.h, which is stack frame 0.

Author: tkent
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/bee5120a945d2d5136c0ddf90f1bad618a96e5b3
Time: Wed Sep 30 07:59:25 2015
The CL last changed line 724 of file Vector.h, which is stack frame 1.

Author: pdr
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/304ec1544273ed8d62c693da6dd2c63727805cdd
Time: Fri Mar 11 05:34:42 2016
The CL last changed line 172 of file SVGTextMetricsBuilder.cpp, which is stack frame 2.

Author: pdr
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/304ec1544273ed8d62c693da6dd2c63727805cdd
Time: Fri Mar 11 05:34:42 2016
The CL last changed line 210 of file SVGTextMetricsBuilder.cpp, which is stack frame 3.

Author: dsinclair@chromium.org
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/50b6c90a032f8258dd5bb91c98c2fa619c124adf
Time: Thu Mar 19 20:59:21 2015
The CL last changed line 250 of file SVGTextMetricsBuilder.cpp, which is stack frame 4.

Author: zimmermann@webkit.org
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/0d1325c12026eefa1bb449608e015f58ef3b49b9
Time: Fri Jan 13 14:18:23 2012
The CL last changed line 280 of file SVGTextMetricsBuilder.cpp, which is stack frame 5.

Author: rob.buis@samsung.com
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/fe430f536c02099278a25381b8a76ba04796b559
Time: Wed Nov 12 00:57:29 2014
The CL last changed line 73 of file SVGTextLayoutAttributesBuilder.cpp, which is stack frame 6.

Suspected Component: chromium
--------------------------------


Suspecting - https://chromium.googlesource.com/chromium/src//+/304ec1544273ed8d62c693da6dd2c63727805cdd ?
@pdr:  Hey, would you mind checking the above issue and see if it's related to your change.

Feel free to re-assign to concern dev if that is not the case.

I really appreciate your help.

Thank you!

Comment 2 by pdr@chromium.org, Mar 22 2016

Mergedinto: 595393
Status: Duplicate (was: Assigned)
I think this is a dupe of 595393. We have a patch in the queue to fix this right now.
Project Member

Comment 3 by ClusterFuzz, Mar 23 2016

ClusterFuzz has detected this issue as fixed in range 382185:382588.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4696095283740672

Fuzzer: inferno_twister
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  ASSERTION FAILED: i < size()
  blink::SVGTextMetricsCalculator::currentCharacterMetrics
  blink::measureTextLayoutObject
  
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=382185:382588

Minimized Testcase (180.31 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96MSDy2eNM7i5HCVuKQniwE4EhXq_gr1NdgXDF_SDpJdEvd7jN1u_8DJBiHdwrA9IBBK6kt510lPBNX2M3ISlTIIxxRTjfL3fuVXNYAbP6XyDEf678BL8JkZWYiyETIJ7fGyzHx1kAFaw23EtNNaPyDd9WaEMtY5l7W4h3lwdQAlOYC6AA

Additional requirements: Requires Gestures

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 4 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment