CHECK failed: isStartOfParagraph(startOfParagraphToMove). #text "\n xxx xxx xx |
|||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5556283947614208 Fuzzer: mbarbella_js_mutation_layout Job Type: linux_debug_content_shell_drt Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: CHECK failed: isStartOfParagraph(startOfParagraphToMove). #text "\n xxx xxx xx blink::CompositeEditCommand::moveParagraph blink::IndentOutdentCommand::outdentParagraph Minimized Testcase (0.41 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv96uV5qpY3mn9H6oOus8erFun4-PDEBBZS9bJ1o7GcuUZaSZ0Z5sS0QHha-flM-fpbPARaH06qqFExXN_miEhxIAObErAZ2-oHYbnOPc_w8layxZysWfNl1Baxy_IEbgNhNqJ8zirrplnS5fDyKjoOcCpcAOwg <div> </div> <div id="mc"</div> xxx xxx xxx xxx xxx xxx xxx xxx xxx <style> * { visibility: visible; } *:only-of-type { visibility: collapse; </style> <script> onload = function() { document.designMode = 'on'; var __v_120 = document.querySelector('blockquote'); getSelection().collapse(__v_120, 2); document.execCommand('Outdent'); }; </script> <blockquote> <table> <table> Filer: manoranjanr See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
May 13 2016
,
Jun 6 2016
,
Jun 10 2016
Lower to Pri-2, real world usage of Outdent command is low.
,
Jul 7 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6335918143438848 Fuzzer: inferno_layout_test_unmodified Job Type: linux_debug_content_shell_drt Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: isStartOfParagraph(startOfParagraphToMove). #text "\n this should be red\n "@ blink::CompositeEditCommand::moveParagraph blink::IndentOutdentCommand::outdentParagraph Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=268656:269696 Minimized Testcase (0.37 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv94Pplq_BnlLA2Er_-Z8i2gAbAyL46siFxAnddCTMxvN5jsTq8a3PZK85yexn2ayfEM2XPNgy4OUn64CQtxSpqqgiEvGMTYP700JNeMa_1E1gdsd8pzrweccdphoINasVtJgAcKGgWVNAtMtadeOwS3IAP4fSg?testcase_id=6335918143438848 <p> this should be red <p> <style> * { visibility: visible; } *:only-of-type { visibility: collapse; </style> <script> onload = function() { document.designMode = 'on'; var __v_106 = document.querySelector('blockquote'); getSelection().collapse(__v_106, 2); document.execCommand('Outdent'); }; </script> <blockquote> <table> <table> Filer: mummareddy See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Oct 18 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Dec 22 2016
ClusterFuzz testcase 5556283947614208 is flaky and no longer reproduces, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
|||||||
►
Sign in to add a comment |
|||||||
Comment 1 by manoranj...@chromium.org
, May 12 2016Labels: Te-Logged
Owner: koten...@yandex-team.ru
Status: Assigned (was: Available)