New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 617918 link

Starred by 0 users

Issue metadata

Status: Duplicate
Merged: issue 616993
Owner:
Closed: Jun 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

adjustedR0 <= adjustedR1

Project Member Reported by ClusterFuzz, Jun 7 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6413676013944832

Fuzzer: mbarbella_js_mutation_layout
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  adjustedR0 <= adjustedR1
  blink::adjustGradientRadiiForOffsetRange
  blink::CSSGradientValue::addStops
  

Minimized Testcase (0.24 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94hXOhEKh8QCf5qGK2r2ACZ_nKRPfHSo0VXvPfi5IP4BBDxpQaSljLEC0VFKISmegzY_9AlCTXapV7wjnqaAr71R-NxFZGHH4Oy6yZ2DjTZxyJNnJ2oPHYqzCEY6nDn43LwkcKwbYE2cPzSVKDbFi9FOOVOiA

Filer: ashejole

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: ashej...@chromium.org
Components: Blink>CSS Tools>Test>FindIt>CorrectResult
Labels: -Pri-1 findit-for-crash Te-Logged M-53 Pri-2
Owner: fmalita@chromium.org
Status: Assigned (was: Available)
Suspected CLs	Regression information is not available. The result is the blame information.

Author: fmalita@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/8d740ea7e1829561233466f984b04b85a10c917d
Time: Wed Feb 25 03:54:05 2015
The CL last changed line 327 of file CSSGradientValue.cpp, which is stack frame 0.

Author: fmalita@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/8d740ea7e1829561233466f984b04b85a10c917d
Time: Wed Feb 25 03:54:05 2015
The CL last changed line 471 of file CSSGradientValue.cpp, which is stack frame 1.

Author: fmalita@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/8d740ea7e1829561233466f984b04b85a10c917d
Time: Wed Feb 25 03:54:05 2015
The CL last changed line 1164 of file CSSGradientValue.cpp, which is stack frame 2.

Author: schenney
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/4afb23eb3dfc2fb9006ce3b69051cc108c241ba5
Time: Tue Mar 15 23:33:47 2016
The CL last changed line 78 of file CSSGradientValue.cpp, which is stack frame 3.

Author: dsinclair@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/da406c2427ae4c64f0b5cc12e69a3125dd4c2717
Time: Mon Apr 27 20:42:41 2015
The CL last changed line 131 of file CSSImageGeneratorValue.cpp, which is stack frame 4.

Author: dsinclair@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/4c40fce76c29acc6e722d6bf48b2c3d761f7cce0
Time: Fri Mar 06 04:41:42 2015
The CL last changed line 73 of file StyleGeneratedImage.cpp, which is stack frame 5.

Author: fmalita
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/4c1400381d16b6dcd8921a8f19a2ae9af4aac4cf
Time: Tue May 24 00:53:09 2016
The CL last changed line 351 of file BoxPainter.cpp, which is stack frame 6.

Suspected Project: chromium
Suspected Component: Blink>CSS

----------------------------------------------------

@fmalita: Hey, would you mind checking the above issue as per above suspected CL which change the file in Frame 1 ?

I really appreciate the help.

Thank y ou!
Cc: infe...@chromium.org
I'm 99% sure this is a dupe of  issue 616993 .

The fix landed at r398029, and it added a new test.  Looks like CF picked up the new test, but ran it against an earlier revision: r398017.

This behavior doesn't make much sense, as it's guaranteed to trigger false positives whenever we land fixes with tests.

@inferno can we teach CF not to look back when finding new tests?
Project Member

Comment 3 by ClusterFuzz, Jun 9 2016

ClusterFuzz has detected this issue as fixed in range 398017:398731.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6413676013944832

Fuzzer: mbarbella_js_mutation_layout
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  adjustedR0 <= adjustedR1
  blink::adjustGradientRadiiForOffsetRange
  blink::CSSGradientValue::addStops
  
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=398017:398731

Minimized Testcase (0.21 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97CfuITKioCVUbalBXuT-7RIthDiiP3t9-qFFIZ0oJMt-vT3zFQD5vsz-cHFVtbxroh74ONWNdDH0swbrSUmRFv9PN-rmftStLLTJDBaEVLaA_5vKThMtB93v8j7JQfzpoOwN5aEzeHatD7bc27HStU3vz_zQ

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Mergedinto: 616993
Status: Duplicate (was: Assigned)

Comment 5 by aarya@google.com, Jun 18 2016

Florin, sorry about that. The problem gets harder since sometimes lkgr can really lag behind. in Some time, lkgr will be converted to tip-of-tree green for specific builder, and then this shouldn't be a problem.
No worries, just wanted to make sure you're aware of this.  Thanks!
Project Member

Comment 7 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment