New issue
Advanced search Search tips

Issue 627060 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner:
Closed: Jul 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Mac
Pri: 2
Type: Bug-Regression



Sign in to add a comment

Crash when doing mousedrag on specific html which triggers replacement of that html

Reported by flug...@gmail.com, Jul 11 2016

Issue description

UserAgent: Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.106 Safari/537.36

Steps to reproduce the problem:
1. Load the attached testcase in a tab
2. Do 2 mousedrags over one of the buttons (press down left mousebutton and move at least 1 pixel before releasing)
3. Exactly at the second drag event, the tab crashes

What is the expected behavior?
It should not crash

What went wrong?
Tab is crashing with "Aw, Snap!"

Crashed report ID: 

How much crashed? Just one tab

Is it a problem with a plugin? No 

Did this work before? N/A 

Chrome version: 51.0.2704.106  Channel: stable
OS Version: 4.6.3-1-ARCH GNU/Linux
Flash Version: Shockwave Flash 11.9 r900

This is about the most minimal testcase I could make. To reproduce it requires 2 button-tags on the page, both requires another tag inside with ::before content set through css. The event must be triggered in a child of the html which is replaced. Note that it works fine if you don't move the mouse while clicking.

See attached html file, or here https://gist.github.com/flugsio/83ca2ac8e78ef70e4de44371150655e8
 
chrome_mousedrag_crash_20161711.html
1.4 KB View Download
Components: Blink>DataTransfer
Labels: -Type-Bug M-51 OS-Mac OS-Windows Type-Bug-Regression
Owner: yoichio@chromium.org
Status: Assigned (was: Unconfirmed)
Able to reproduce the issue on Mac 10.11.5, Win 7 and Ubuntu 14.04 using stable 51.0.2704.106(094509b600000000,cd3a910900000000).
Unable to reproduce the same on latest canary 54.0.2794.0.
The stack is similar to issue 562339.
yoichio@ : Assigning to you based on the earlier work done on similar issue.Could you please take a look into this and update further on it.
Components: -Blink>DataTransfer Blink>Editing
Status: WontFix (was: Assigned)
Not repro on Version 61.0.3154.4 (Official Build) canary (64-bit)

Sign in to add a comment