Crash in blink::FrameView::trackedObjectPaintInvalidationsAsJSON |
|||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5776866155954176 Fuzzer: inferno_twister Job Type: windows_syzyasan_content_shell Platform Id: windows Crash Type: UNKNOWN Crash Address: 0x00000003 Crash State: blink::FrameView::trackedObjectPaintInvalidationsAsJSON blink::LocalFrame::layerTreeAsText blink::Internals::layerTreeAsText Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=411207:411233 Minimized Testcase (4.82 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95tByaEWURZ0gFnqjsdn5Bz6rTbGJQlF_mRnKo0uJwzmVy5eQ2vvsWa0v_3EypnxllIz1OBJSXCpc_6tYF50ZOYmrUYxJxcz1b0zqHHqkCgxtxfzQJHSUszC3hJV92fIh-VFOVfN0y42YZAAkE1fBnWWuoYgA?testcase_id=5776866155954176 Issue manually filed by: nyerramilli See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Aug 16 2016
danakj, any chance this is fallout from https://codereview.chromium.org/2034583002? If not, nyerramilli, could you assign to one of the frame owners?
,
Aug 16 2016
No, that is very separate from blink, and in another process.
,
Aug 16 2016
rune@, Could you please check the above issue & help us in finding an owner. Thanks in advance..
,
Aug 16 2016
,
Aug 16 2016
wangxianzhu@chromium.org showed up in that area of the code when blaming, but the cause may be somewhere else.
,
Aug 16 2016
This happens in carelessly written layout test only.
,
Aug 16 2016
Let's make it not crash.
,
Aug 16 2016
The test crashes because it finishes when runRunner.layoutAndPaintAsyncThen(). A real layout test can easily avoid such crashes with waitUntilDone() and notifyDone(). Will not put effort on this.
,
Oct 18 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||
►
Sign in to add a comment |
|||||||||||
Comment 1 by nyerramilli@chromium.org
, Aug 11 2016Components: Tools>Test>FindIt>NoResult
Labels: findit-wrong TE-Triaged Te-Logged
Owner: dgro...@chromium.org
Status: Assigned (was: Untriaged)