ASSERTION FAILED: !std::isnan(static_cast<double>(value)) |
|||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5263340766494720 Fuzzer: mbarbella_js_mutation_layout Job Type: linux_debug_content_shell_drt Platform Id: linux Crash Type: ASSERT Crash Address: Crash State: ASSERTION FAILED: !std::isnan(static_cast<double>(value)) int clampTo<int, float> blink::LayoutUnit::fromFloatCeil Minimized Testcase (0.50 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96zFdpGwsfkj11S5R1Vskd3NMdroGN1o9_Cbb5CrVOWZE6ZrXiWMmJTIGrOK6350zghe80SSc74KDfv9UJu_IUKPulMjOwX--pRw45wD6EYUjHlYP9nfYL5H5urXR-41tcaa1pB4RSz3X8LtDrnVELletJttw Filer: manoranjanr See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Mar 24 2016
,
Mar 25 2016
,
Mar 29 2016
eae@ to triage for layout-dev.
,
Apr 19 2016
,
Apr 20 2016
,
Apr 20 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/fa1ff2fb43ff5538f6950be40cd7f3751af22678 commit fa1ff2fb43ff5538f6950be40cd7f3751af22678 Author: eae <eae@chromium.org> Date: Wed Apr 20 00:25:34 2016 Handle very large transforms in ContainerNode::boundingBox Change ContainerNode::boundingBox to explicitly check for and handle NaN sizes. Very large matrix and scale transforms may result in a NaN value. BUG= 597846 TEST=fast/transforms/focus-on-transformed-node.htm R=szager@chromium.org Review URL: https://codereview.chromium.org/1903493003 Cr-Commit-Position: refs/heads/master@{#388374} [add] https://crrev.com/fa1ff2fb43ff5538f6950be40cd7f3751af22678/third_party/WebKit/LayoutTests/fast/transforms/focus-on-transformed-node-expected.txt [add] https://crrev.com/fa1ff2fb43ff5538f6950be40cd7f3751af22678/third_party/WebKit/LayoutTests/fast/transforms/focus-on-transformed-node.html [modify] https://crrev.com/fa1ff2fb43ff5538f6950be40cd7f3751af22678/third_party/WebKit/Source/core/dom/ContainerNode.cpp
,
Apr 20 2016
ClusterFuzz has detected this issue as fixed in range 388350:388383. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5263340766494720 Fuzzer: mbarbella_js_mutation_layout Job Type: linux_debug_content_shell_drt Platform Id: linux Crash Type: ASSERT Crash Address: Crash State: ASSERTION FAILED: !std::isnan(static_cast<double>(value)) int clampTo<int, float> blink::LayoutUnit::fromFloatCeil Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=388350:388383 Minimized Testcase (0.50 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96zFdpGwsfkj11S5R1Vskd3NMdroGN1o9_Cbb5CrVOWZE6ZrXiWMmJTIGrOK6350zghe80SSc74KDfv9UJu_IUKPulMjOwX--pRw45wD6EYUjHlYP9nfYL5H5urXR-41tcaa1pB4RSz3X8LtDrnVELletJttw See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||
►
Sign in to add a comment |
|||||||
Comment 1 by manoranj...@chromium.org
, Mar 24 2016Components: Blink>Layout
Labels: findit-for-crash Te-Logged
Owner: dsinclair@chromium.org
Status: Assigned (was: Available)