New issue
Advanced search Search tips

Issue 627053 link

Starred by 0 users

Issue metadata

Status: Duplicate
Merged: issue 546794
Owner:
Closed: Jul 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

mainAxisExtent - mainAxisBorderAndPaddingExtentForChild(child) >= 0

Project Member Reported by ClusterFuzz, Jul 11 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5113497017122816

Fuzzer: inferno_twister
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  mainAxisExtent - mainAxisBorderAndPaddingExtentForChild(child) >= 0
  blink::LayoutFlexibleBox::computeInnerFlexBaseSizeForChild
  blink::LayoutFlexibleBox::computeNextFlexLine
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=268656:269696

Minimized Testcase (0.50 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv94sEiAH6O9UhGVb_piOJOUmHmGqI7ELhVsmNrBWIJEk7AWm_HlgufU-Se-Zh0ETlgFPVTYgun38G32qkVsfV40ikjFelnTpCaxGOak59lBQJSjWJ2bAwGEZgfMXALYAf55OATZfTX2pVNjdO_tFp4xVsVlBhA?testcase_id=5113497017122816
<body id=tCF1>oE@	SGuW#	  %-Km&amp;<style>
.c8:not([title*="on ch"]) { column-count: inherit; padding-left: calc(94% - 48px);</style><script>
var docElement = document.body ? document.body : document.documentElement;
tCF4 = document.createElementNS("http://www.w3.org/1999/xhtml", "rtc");
tCF1.appendChild(tCF4);
tCF15 = document.createElementNS("http://www.w3.org/1999/xhtml", "c");
docElement.appendChild(tCF15);
tCF4.classList.toggle("c8");
tCF15.parentNode.style.display = "-webkit-inline-flex"
</script>


Filer: kavvaru

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Components: Blink>Layout>Flexbox Tools>Test>FindIt>CorrectResult
Labels: Te-Logged
Owner: cbiesin...@chromium.org
Status: Assigned (was: Available)
Find it tool result
==================
	No CL in the regression range changes the crashed files. The result is the blame information.

Author: cbiesinger
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/33e4afcb97d048986b974ff70de8fd9d0959d838
Time: Mon Feb 01 23:52:47 2016
The CL last changed line 850 of file LayoutFlexibleBox.cpp, which is stack frame 0.

Author: cbiesinger
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/bd50d003d8585043b1f016330ea68f157fae5f41
Time: Wed Jul 06 23:34:48 2016
The CL last changed line 1218 of file LayoutFlexibleBox.cpp, which is stack frame 1.

Author: cbiesinger
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/36921b28f83a30d8d0caaa408b1586afed2ca323
Time: Thu Nov 26 03:54:17 2015
The CL last changed line 868 of file LayoutFlexibleBox.cpp, which is stack frame 2.

Author: mstensho@opera.com
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/ea19b30f8665daf092f41d3fd62f9bfe99fcc18e
Time: Tue Jun 09 20:02:03 2015
The CL last changed line 359 of file LayoutFlexibleBox.cpp, which is stack frame 3.

Author: hyatt
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/d7dafcfaea34d563b00b5149b94575261464b857
Time: Tue Apr 29 23:32:54 2003
The CL last changed line 373 of file LayoutBlock.cpp, which is stack frame 4.

Author: dsinclair@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/8c100aa6fafc0738675c73b79788b6d8163fb0ce
Time: Fri Feb 06 00:05:44 2015
The CL last changed line 900 of file LayoutObject.h, which is stack frame 5.

Author: mstensho
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/b56f9c5e4843967306e2fa249d7228394b3de930
Time: Fri Apr 29 21:26:48 2016
The CL last changed line 1588 of file LayoutBlockFlowLine.cpp, which is stack frame 6.

Suspected Project: chromium-blink
Suspected Component: Blink>Layout
==========================
From the above the changes made to the file LayoutFlexibleBox.cpp from frame #0,2 are more related.

cbiesinger@ could you please look into this issue if it is rlated to your change,else please help us in finding the appropriate owner for this issue.

Thanks,

Mergedinto: 546794
Status: Duplicate (was: Assigned)
Project Member

Comment 3 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 4 by ClusterFuzz, Jan 1 2017

ClusterFuzz has detected this issue as fixed in range 405740:405744.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5113497017122816

Fuzzer: inferno_twister
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  mainAxisExtent - mainAxisBorderAndPaddingExtentForChild(child) >= 0
  blink::LayoutFlexibleBox::computeInnerFlexBaseSizeForChild
  blink::LayoutFlexibleBox::computeNextFlexLine
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=268656:269696
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=405740:405744

Minimized Testcase (0.50 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv94sEiAH6O9UhGVb_piOJOUmHmGqI7ELhVsmNrBWIJEk7AWm_HlgufU-Se-Zh0ETlgFPVTYgun38G32qkVsfV40ikjFelnTpCaxGOak59lBQJSjWJ2bAwGEZgfMXALYAf55OATZfTX2pVNjdO_tFp4xVsVlBhA?testcase_id=5113497017122816
<body id=tCF1>oE@	SGuW#	  %-Km&amp;<style>
.c8:not([title*="on ch"]) { column-count: inherit; padding-left: calc(94% - 48px);</style><script>
var docElement = document.body ? document.body : document.documentElement;
tCF4 = document.createElementNS("http://www.w3.org/1999/xhtml", "rtc");
tCF1.appendChild(tCF4);
tCF15 = document.createElementNS("http://www.w3.org/1999/xhtml", "c");
docElement.appendChild(tCF15);
tCF4.classList.toggle("c8");
tCF15.parentNode.style.display = "-webkit-inline-flex"
</script>


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Sign in to add a comment