Issue metadata
Sign in to add a comment
|
ASSERTION FAILED: contentSize >= 0 |
||||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5402304328499200 Fuzzer: inferno_twister Job Type: linux_debug_content_shell_drt Platform Id: linux Crash Type: ASSERT Crash Address: Crash State: ASSERTION FAILED: contentSize >= 0 blink::LayoutFlexibleBox::adjustChildSizeForMinAndMax blink::LayoutFlexibleBox::computeNextFlexLine Minimized Testcase (0.28 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv96rAFWjMnpKVco2uyq9K-mrfih4ajwMZu3_1wtr-dVLzaUzqsMN6FKm_R-9gnDXIqKVm3HS_ToUKFjhL0VTNU1MOxofuP-vHPOV2QUpukVFE_DyTmR0Z-6QlBr67nnazwKOm2ORMTPqKwgrwmhq-o-R222dew <style>div { height: 8em; display: flex } span { margin: 1em 0; flex: 0 0 50% </style> <div> <span>four<style> * { animation-name: cfpulse74; max-height: -webkit-fit-content;</style><style> * { animation-name: cfpulse93;90px); padding-top: 67%;58%); writing-mode: tb-rl; Filer: ssamanoori See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 19 2016
essentially the same issue as bug 397449 (via bug 492678 )
,
Jul 28 2016
ClusterFuzz has detected this issue as fixed in range 408165:408183. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5402304328499200 Fuzzer: inferno_twister Job Type: linux_debug_content_shell_drt Platform Id: linux Crash Type: ASSERT Crash Address: Crash State: contentSize >= 0 blink::LayoutFlexibleBox::adjustChildSizeForMinAndMax blink::LayoutFlexibleBox::computeNextFlexLine Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=356784:357068 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=408165:408183 Minimized Testcase (0.33 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv96KTpAs3BEopZsaXmY6bfIS-9M-KizKh1hdHOkgq5COrpOIpMO03BBYevpQyR9BE2IV7JS3W23PpTAIJqZoBdqDfoV6pgjJm2VwAPBAYJsY0FPAI8JC8h1nclbGIb5_m48uFTn8hzRLjdRm-lHCmyoEqhMZbA?testcase_id=5402304328499200 <style>div { height: 8em; display: flex } span { margin: 1em 0; flex: 0 0 50% </style> <div> <span>four<style> * { animation-name: cfpulse74; max-height: -webkit-fit-content; }<style> @keyframes cfpulse1 { 0% { opacity: 0.9997; } } * { animation-name: cfpulse93;90px); padding-top: 67%;58%); writing-mode: tb-rl; See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jul 28 2016
(not technically fixed, just using dcheck instead of assert now: [1:1:0728/140050:1478869916156:FATAL:LayoutFlexibleBox.cpp(1123)] Check failed: contentSize >= LayoutUnit() (-13.8281 vs. 0) but since this a dup anyway, that should be fine)
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by ssamanoori@chromium.org
, Apr 19 2016Labels: findit-for-crash M-50 Te-Logged
Owner: cbiesin...@chromium.org
Status: Assigned (was: Available)