New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 608520 link

Starred by 0 users

Issue metadata

Status: Verified
Owner:
NOT IN USE
Closed: Aug 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

ASSERTION FAILED: isFirstAfterBreak(lineTopInFlowThread) || !line.paginationStru

Project Member Reported by ClusterFuzz, May 2 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4602503487815680

Fuzzer: inferno_twister
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  ASSERTION FAILED: isFirstAfterBreak(lineTopInFlowThread) || !line.paginationStru
  blink::MinimumSpaceShortageFinder::examineLine
  blink::ColumnBalancer::traverseSubtree
  

Minimized Testcase (0.29 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv94kuOtP9RKymwyTHaMHUjDbhwu5ErbWJcS_E7QZGrOYQVCui9ChbAmg2Z7Ad9lwQ7ab_T3Umvk8MIEjfQsduDQhN4vHrupJBJxKaZjhsklPfB0vfhWdtoH-UDNWKGsWX-OVuQz5g17jVHhasxaq8pxdy7jDCw
<div style="-webkit-columns:2;">
    <br>
    <div style=height:1em;>1?X3it?kf^jwyIP	r|*7g_l(IK
G!N
j*
ACx]4j	jpm~fa!xiT[o	
cgV
4;(	bIS-/W97^R	? 9 CjjCTt0t3g5
 NS~rc	Tzk=^c!LK | bT 	
7_{CrO%&amp;{h[%5UxGVy:|y91	ChU0uq
r5]T!
	XT AVzJrkz9z2
        <div style=-webkit-column-span:all;></div>
    <br>


Filer: pucchakayala

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Components: Blink>Layout Tools>Test>FindIt>CorrectResult
Labels: Te-Logged M-51
Owner: msten...@opera.com
Status: Assigned (was: Available)
Suspected CLs	Regression information is not available. The result is the blame information.

Author: mstensho
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/904d6b10d8b45a9a3c5933e7252c7d2ee31cb608
Time: Wed Dec 09 11:35:12 2015
The CL last changed line 332 of file ColumnBalancer.cpp, which is stack frame 0.

Author: mstensho
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/ce77a26bc7b22cf511e91b336f40ae405712f66b
Time: Sat Oct 10 10:00:40 2015
The CL last changed line 36 of file ColumnBalancer.cpp, which is stack frame 1.

Author: mstensho
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/ce77a26bc7b22cf511e91b336f40ae405712f66b
Time: Sat Oct 10 10:00:40 2015
The CL last changed line 77 of file ColumnBalancer.cpp, which is stack frame 2.

Author: mstensho
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/ce77a26bc7b22cf511e91b336f40ae405712f66b
Time: Sat Oct 10 10:00:40 2015
The CL last changed line 77 of file ColumnBalancer.cpp, which is stack frame 3.

Author: mstensho
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/5b65a57f38f0260e21b8ec190d201ae2504d73e5
Time: Mon Apr 18 23:16:17 2016
The CL last changed line 22 of file ColumnBalancer.cpp, which is stack frame 4.

Author: mstensho
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/ce77a26bc7b22cf511e91b336f40ae405712f66b
Time: Sat Oct 10 10:00:40 2015
The CL last changed line 243 of file ColumnBalancer.cpp, which is stack frame 5.

Author: mstensho
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/5b65a57f38f0260e21b8ec190d201ae2504d73e5
Time: Mon Apr 18 23:16:17 2016
The CL last changed line 342 of file MultiColumnFragmentainerGroup.cpp, which is stack frame 6.

Suspected Project: chromium
Suspected Component: Blink>Layout


Comment 2 by msten...@opera.com, Aug 11 2016

Labels: -ClusterFuzz Clusterfuzz
I'm working on a fix for  bug 633411 , and that fix seems to fix the minimized test case, but the full test still crashes.
Project Member

Comment 3 by ClusterFuzz, Aug 13 2016

ClusterFuzz has detected this issue as fixed in range 411340:411371.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4602503487815680

Fuzzer: inferno_twister
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  isFirstAfterBreak(lineTopInFlowThread) || !line.paginationStrut() || !isLogicalT
  blink::MinimumSpaceShortageFinder::examineLine
  blink::ColumnBalancer::traverseSubtree
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=388749:389333
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=411340:411371

Minimized Testcase (0.29 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv94_CzJrXIba8R9lnR8Bzy8hQFW3ZCWNCZRY_-X1qznPtOgezZpw3WVHPXEmyUL6V0pXBZDeeE_dbkT5UFHuOkeIz8q49gFzZlJEEhbjoHqSsOPWv3uyETjoCWBcAXZnK1y7LfLKEifW56SIit_XBerRbQpANg?testcase_id=4602503487815680
<div style="-webkit-columns:2;">
    <br>
    <div style=height:1em;>1?X3it?kf^jwyIP	r|*7g_l(IK
G!N
j*
ACx]4j	jpm~fa!xiT[o	
cgV
4;(	bIS-/W97^R	? 9 CjjCTt0t3g5
 NS~rc	Tzk=^c!LK | bT 	
7_{CrO%&amp;{h[%5UxGVy:|y91	ChU0uq
r5]T!
	XT AVzJrkz9z2
        <div style=-webkit-column-span:all;></div>
    <br>


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 4 by ClusterFuzz, Aug 13 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 5 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment