!floatingObject->originatingLine() |
||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6606610594267136 Fuzzer: inferno_layout_test_unmodified Job Type: linux_debug_content_shell_drt Platform Id: linux Crash Type: ASSERT Crash Address: Crash State: !floatingObject->originatingLine() blink::LayoutBlockFlow::linkToEndLineIfNeeded blink::LayoutBlockFlow::layoutRunsAndFloats Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=268656:269696 Minimized Testcase (0.56 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95AB4nmROI3WeFD8XDClkp6qOqamTGjfT2XszoDgL4Or2mJQsitKxuaK7JtTwPlLrZgDvzfm3kINJCUE189Q-EXeRrG3q22y2wrsjIwxSpGA8f5xphHEtVAfK0EB-VqJ34mci_hkoCuvGh6i90vuvpkzMjAZA?testcase_id=6606610594267136 Issue manually filed by: durga.behera See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Aug 26 2016
Leaving to layout team
,
Aug 26 2016
,
Oct 18 2016
,
Nov 2 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Dec 22 2016
ClusterFuzz testcase 6606610594267136 is flaky and no longer reproduces, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Dec 23 2016
I can still reproduce this.
,
Mar 16 2017
,
Mar 23 2017
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/068a38e0f20762a3f218a88aba3290ad83d6e255 commit 068a38e0f20762a3f218a88aba3290ad83d6e255 Author: robhogan <robhogan@gmail.com> Date: Thu Mar 23 12:05:58 2017 Ensure line-break is on correct object if trailing collapsed whitespace pushes us over line-end If we're going to break on an auto-wrap line due to trailing space make sure the line break has been moved to the next available next layout object on the line. BUG= 641334 Review-Url: https://codereview.chromium.org/2479333002 Cr-Commit-Position: refs/heads/master@{#459052} [modify] https://crrev.com/068a38e0f20762a3f218a88aba3290ad83d6e255/third_party/WebKit/LayoutTests/TestExpectations [add] https://crrev.com/068a38e0f20762a3f218a88aba3290ad83d6e255/third_party/WebKit/LayoutTests/fast/block/float/assert-when-moving-float-expected.txt [add] https://crrev.com/068a38e0f20762a3f218a88aba3290ad83d6e255/third_party/WebKit/LayoutTests/fast/block/float/assert-when-moving-float.html [modify] https://crrev.com/068a38e0f20762a3f218a88aba3290ad83d6e255/third_party/WebKit/Source/core/layout/line/BreakingContextInlineHeaders.h
,
Jun 15 2017
,
Jul 14 2017
ClusterFuzz testcase 5257108166803456 is still reproducing on tip-of-tree build (trunk). Please re-test your fix against this testcase and if the fix was incorrect or incomplete, please re-open the bug. Otherwise, ignore this notification and add ClusterFuzz-Wrong label.
,
Jul 20 2017
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/f9304249c8addb03fe449f9eb8c638f5c69d323e commit f9304249c8addb03fe449f9eb8c638f5c69d323e Author: Robert Hogan <robhogan@gmail.com> Date: Thu Jul 20 01:18:13 2017 Ensure line-break is on correct object if trailing collapsed whitespace pushes us over line-end A follow-up to https://codereview.chromium.org/2479333002. Bug: 641334 Change-Id: If0e92b89422b3f9406d5f8d10fec2d90f83f0e06 Reviewed-on: https://chromium-review.googlesource.com/573500 Commit-Queue: Emil A Eklund <eae@chromium.org> Reviewed-by: Emil A Eklund <eae@chromium.org> Cr-Commit-Position: refs/heads/master@{#488076} [add] https://crrev.com/f9304249c8addb03fe449f9eb8c638f5c69d323e/third_party/WebKit/LayoutTests/fast/block/float/assert-when-moving-float-2-expected.txt [add] https://crrev.com/f9304249c8addb03fe449f9eb8c638f5c69d323e/third_party/WebKit/LayoutTests/fast/block/float/assert-when-moving-float-2.html [modify] https://crrev.com/f9304249c8addb03fe449f9eb8c638f5c69d323e/third_party/WebKit/Source/core/layout/line/BreakingContextInlineHeaders.h |
||||||||||
►
Sign in to add a comment |
||||||||||
Comment 1 by durga.behera@chromium.org
, Aug 26 2016Labels: Te-Logged M-52
Owner: wangxianzhu@chromium.org
Status: Assigned (was: Untriaged)