Crash in blink::PaintLayer::isSelfPaintingLayer |
|||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5807910672400384 Fuzzer: inferno_twister Job Type: linux_debug_content_shell_drt Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000008 Crash State: blink::PaintLayer::isSelfPaintingLayer blink::BoxClipper::BoxClipper blink::BlockPainter::paint Minimized Testcase (3.62 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94WfQKzO8709SobxZmFLT-cjhxzm6j1Gy_Akr-2WzciyBR4nxHN4FPHlA7F50IehHYfVrdOk_Y9fDtSRcn772YbnNle5Hb96mQLbwJ7MWXLb25hkyBQ66EqueClfxiWjOOQhQqIMsaetnGAc_A4lG7iuDw8ig Filer: ashejole See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jun 8 2016
This looks like it could be a dupe of issue 613929.
,
Jun 9 2016
Yes, this bug is also about LayoutSVGText which doesn't have a layer.
,
Jun 21 2016
ClusterFuzz has detected this issue as fixed in range 399276:400924. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5807910672400384 Fuzzer: inferno_twister Job Type: linux_debug_content_shell_drt Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000008 Crash State: blink::PaintLayer::isSelfPaintingLayer blink::BoxClipper::BoxClipper blink::BlockPainter::paint Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=398006:398016 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=399276:400924 Minimized Testcase (3.62 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94aCafkpkp6WS8B4c787sFEv2tKBQiAhaina329v1HtHR9w6bvHIdpGWAc0iv0Dpn4q4VgNfzTDcngGhQ6ycySCFR1EVBO-uGGX3SnAHQD3vzUHUY-QaM5CkUhqt9TFYNsbQfBlZOkfUmSnYGz5cfr3W_qYug?testcase_id=5807910672400384 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||
►
Sign in to add a comment |
|||
Comment 1 by ashej...@chromium.org
, Jun 8 2016Components: Tools>Test>FindIt>CorrectResult Blink>Paint
Labels: findit-for-crash Te-Logged
Owner: wangxianzhu@chromium.org
Status: Assigned (was: Available)