ASSERTION FAILED: !std::isnan(static_cast<double>(value)) |
|||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5287112748564480 Fuzzer: inferno_twister_custom_bundle Job Type: linux_debug_chrome Platform Id: linux Crash Type: ASSERT Crash Address: Crash State: !std::isnan(static_cast<double>(value)) int clampTo<int, float> blink::LayoutUnit::fromFloatFloor Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_chrome&range=340068:340069 Minimized Testcase (2.04 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94p_ETSti3kH0OTwxGq_Jc3lNX1FmICODNBTSx5DjcH-9HV8440K34HxJqEEjNIRGv25QmbQw4yHWaT-kZ1DImrlKtPgoU2ug0Ej_p90aiBe6VjuLOoBS3b0pOmDSOfdkub1RpbpXxnK1ezv0uE1nyipLiZ_A?testcase_id=5287112748564480 Filer: nyerramilli See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jul 11 2016
,
Jul 11 2016
Turns out this isn't animation related, smaller test case:
<style>
body {
motion: path("M 2 9223372036854775640 h 112 v 18446744073709551478") 170141183460469231731687303715884105727rad 44px;
}
</style>
,
Jul 12 2016
ClusterFuzz has detected this issue as fixed in range 404631:404810. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5287112748564480 Fuzzer: inferno_twister_custom_bundle Job Type: linux_debug_chrome Platform Id: linux Crash Type: ASSERT Crash Address: Crash State: !std::isnan(static_cast<double>(value)) int clampTo<int, float> blink::LayoutUnit::fromFloatFloor Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_chrome&range=340068:340069 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_chrome&range=404631:404810 Minimized Testcase (2.04 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94p_ETSti3kH0OTwxGq_Jc3lNX1FmICODNBTSx5DjcH-9HV8440K34HxJqEEjNIRGv25QmbQw4yHWaT-kZ1DImrlKtPgoU2ug0Ej_p90aiBe6VjuLOoBS3b0pOmDSOfdkub1RpbpXxnK1ezv0uE1nyipLiZ_A?testcase_id=5287112748564480 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jul 12 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Jul 14 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/f87864e5a3a216df836abe7bdc798d49dec9866c commit f87864e5a3a216df836abe7bdc798d49dec9866c Author: alancutter <alancutter@chromium.org> Date: Thu Jul 14 01:05:39 2016 Avoid overflowing motion-rotation when converting double to float BUG= 626994 Review-Url: https://codereview.chromium.org/2135913002 Cr-Commit-Position: refs/heads/master@{#405378} [add] https://crrev.com/f87864e5a3a216df836abe7bdc798d49dec9866c/third_party/WebKit/LayoutTests/css3/motion-path/motion-rotation-overflow-crash.html [modify] https://crrev.com/f87864e5a3a216df836abe7bdc798d49dec9866c/third_party/WebKit/Source/core/css/resolver/StyleBuilderConverter.cpp
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||
►
Sign in to add a comment |
|||||
Comment 1 by nyerramilli@chromium.org
, Jul 11 2016Components: Tools>Test>FindIt>WrongResult
Labels: findit-wrong Te-Logged M-52
Owner: alancutter@chromium.org
Status: Assigned (was: Available)