New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 638000 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Aug 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug



Sign in to add a comment

Crash in blink::LayoutBox::clippingRect

Project Member Reported by ClusterFuzz, Aug 15 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5531282400608256

Fuzzer: inferno_twister
Job Type: windows_syzyasan_content_shell
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 
Crash State:
  blink::LayoutBox::clippingRect
  blink::PaintInvalidationState::updateForNormalChildren
  blink::PaintInvalidationState::updateForChildren
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=411924:411925

Minimized Testcase (3.54 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94oM8QeEqZ3_ZcCqyXM8zGVubjdsHlIzwAxVC8cd9Kyt-HQTxT8nfUApAZ-etgFTg1ZDqb12aPnFHoCHJPM0Y1_1Vok9I1-1ZPBzHtpPNUvE2aMxmTmDJf-BmY93TkfwXgEYwI0GPfXFw3rSSaj79OsARd-pg?testcase_id=5531282400608256

Issue manually filed by: mummareddy

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Labels: Test-Layout M-54 Te-Logged
Owner: chrishtr@chromium.org
Status: Assigned (was: Untriaged)
Below one copied from another similar crash 

The result is a list of CLs that change the crashed files.

Author: chrishtr
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/3d30a67e378ec3fcaac5809305584bbabca88e18
Time: Sat Aug 13 01:17:59 2016
Lines 327 of file PaintInvalidationState.cpp which potentially caused crash are changed in this cl (frame #3, "content_shell!blink::PaintInvalidationState::updateForNormalChildren+0x16d").
Minimum distance from crash line to modified line: 0. (file: PaintInvalidationState.cpp, crashed on: 324, modified: 324).

Suspected Project: chromium
Suspected Component: Blink>Layout
Project Member

Comment 2 by ClusterFuzz, Aug 15 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5319621882413056

Fuzzer: inferno_twister
Job Type: windows_syzyasan_content_shell
Platform Id: windows

Crash Type: UNKNOWN
Crash Address: 0x00000033
Crash State:
  blink::PaintInvalidationState::addClipRectRelativeToPaintOffset
  blink::PaintInvalidationState::updateForNormalChildren
  blink::PaintInvalidationState::updateForChildren
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=411529:411868

Minimized Testcase (2.91 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95Ph46w6FUSBnxa632Jv0BOw-w-cK0G417OI9Y9ea4u1iMi_pnptUlhD3FUmQ5X7b-jjfmXxUN9Q5wT4qdwn-0mHIUl4llo8f9WWuXxlJLO02QL7zjNAhhHrmxldW4mNhTyeGWRjZbPOivcLzDrAaTF0HaEfg?testcase_id=5319621882413056

Issue manually filed by: mummareddy

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Project Member

Comment 3 by ClusterFuzz, Aug 16 2016

Labels: Stability-Memory-AddressSanitizer
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4661750400286720

Fuzzer: inferno_twister
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  object.isBox()
  blink::toLayoutBox
  blink::PaintInvalidationState::updateForNormalChildren
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=411529:411868

Minimized Testcase (3.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95cutLRiW24WmNFPHNn3OPS2mcM0pxvGEe9KCIrwPmCQ-rdCPYXQW436w4mAfVJea2rHPFGniRS8veyQORSQwPhSvfWqnDv2xs5Wvds7AOBpaBPG5refzBcNqIFmt0pIBofMQlGf5wCjVtdKGgJ0qYfklEEvw?testcase_id=4661750400286720

Issue manually filed by: mummareddy

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Project Member

Comment 4 by ClusterFuzz, Aug 17 2016

ClusterFuzz has detected this issue as fixed in range 412308:412331.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4661750400286720

Fuzzer: inferno_twister
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  object.isBox()
  blink::toLayoutBox
  blink::PaintInvalidationState::updateForNormalChildren
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=411529:411868
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=412308:412331

Minimized Testcase (3.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95cutLRiW24WmNFPHNn3OPS2mcM0pxvGEe9KCIrwPmCQ-rdCPYXQW436w4mAfVJea2rHPFGniRS8veyQORSQwPhSvfWqnDv2xs5Wvds7AOBpaBPG5refzBcNqIFmt0pIBofMQlGf5wCjVtdKGgJ0qYfklEEvw?testcase_id=4661750400286720

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Status: Fixed (was: Assigned)
As per comment#4, marking the bug as fixed. thank you.
Status: Verified (was: Fixed)
Project Member

Comment 7 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment