New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 619030 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 604095
Owner:
Use other robhogan account instead.
Closed: Jun 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

interval.low() == m_layoutObject->logicalTopForFloat(floatingObject)

Project Member Reported by ClusterFuzz, Jun 10 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6431976030732288

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  interval.low() == m_layoutObject->logicalTopForFloat(floatingObject)
  blink::ComputeFloatOffsetAdapter<
  void blink::PODIntervalTree<blink::LayoutUnit, blink::FloatingObject*>::searchFo
  

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv943Zp0e0aNIKpWOPLKAUrcVBa2IMALvaJ490Yh53gs-q0wstEH5wKkWXQYm1s5ZzDw_CejkXK0QLNxFc2AlTHwIMPbRU-RFDpLNhlXTU5dnB5VAKuTzMECqn7v9_hObf_QBlKqg0smDYNWyXMThFwbUO4QAxw


Filer: ashejole

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: ashej...@chromium.org
Components: Blink>Layout Tools>Test>FindIt>CorrectResult
Labels: findit-for-crash Te-Logged
Owner: robhogan@chromium.org
Status: Assigned (was: Available)
Suspected CLs	Regression information is not available. The result is the blame information.

Author: robhogan
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/f72d927cdfb1b9a4c3db0a06907238a3cac3dbb0
Time: Fri Oct 23 00:00:09 2015
The CL last changed line 587 of file FloatingObjects.cpp, which is stack frame 0.

Author: hyatt@apple.com
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/fb381ad1e14b63ba01af6b787575f71d5fbe304a
Time: Tue Aug 09 19:13:45 2011
The CL last changed line 176 of file PODIntervalTree.h, which is stack frame 1.

Author: hyatt@apple.com
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/fb381ad1e14b63ba01af6b787575f71d5fbe304a
Time: Tue Aug 09 19:13:45 2011
The CL last changed line 126 of file PODIntervalTree.h, which is stack frame 2.

Author: bjonesbe@adobe.com
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/242fcee6681f9b875edbc7251c5e279d75a4f519
Time: Fri Nov 08 21:58:16 2013
The CL last changed line 531 of file FloatingObjects.cpp, which is stack frame 3.

Author: bjonesbe@adobe.com
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/242fcee6681f9b875edbc7251c5e279d75a4f519
Time: Fri Nov 08 21:58:16 2013
The CL last changed line 3389 of file LayoutBlockFlow.cpp, which is stack frame 4.

Author: leviw@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/1a0cdfc6ab2eb97b69b30966a17c6ff3fee07061
Time: Tue Jan 07 10:01:16 2014
The CL last changed line 331 of file LayoutBlockFlow.h, which is stack frame 5.

Author: robhogan
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/4827508d33eda3f39fa999e53d11998695f45c4f
Time: Fri Jan 15 18:43:26 2016
The CL last changed line 116 of file LayoutBlockFlow.h, which is stack frame 6.

Suspected Project: chromium
Suspected Component: Blink>Layout
----------------------------------

robhogan@: Hey, would you mind checking the above issue as per above findit suspected CL result ?

Appreciate your help.

Thank you!
Mergedinto: 604095
Status: Duplicate (was: Assigned)
Project Member

Comment 3 by ClusterFuzz, Jun 17 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6431976030732288

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  interval.low() == m_layoutObject->logicalTopForFloat(floatingObject)
  blink::ComputeFloatOffsetAdapter<
  void blink::PODIntervalTree<blink::LayoutUnit, blink::FloatingObject*>::searchFo
  

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv943Zp0e0aNIKpWOPLKAUrcVBa2IMALvaJ490Yh53gs-q0wstEH5wKkWXQYm1s5ZzDw_CejkXK0QLNxFc2AlTHwIMPbRU-RFDpLNhlXTU5dnB5VAKuTzMECqn7v9_hObf_QBlKqg0smDYNWyXMThFwbUO4QAxw


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 4 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment