New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 642314 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Feb 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Bug



Sign in to add a comment

layoutObject == node->layoutObject()tree should not changed in CaretBase.cpp

Project Member Reported by ClusterFuzz, Aug 30 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4625137179820032

Fuzzer: bj_broddelwerk
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: CHECK failure
Crash Address: 
Crash State:
  layoutObject == node->layoutObject()tree should not changed in CaretBase.cpp
  blink::CaretBase::caretLayoutObject
  blink::CaretBase::invalidateLocalCaretRect
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=395786:395828

Minimized Testcase (3.58 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94Wn-a0eJ0rKjztqsUy1BuGoHm4D7gs_pZjtW0zRJWmkId5-WjaBf5Tn1b2tIpuxkH_Qjoq23WK_YpHxSEYqs40JHxsPRG4ovnNBz7QK5hkAegIsfLwM8du4KMJz_JCxuUfZC21pSvKAujekGv7DywWvQCjDw?testcase_id=4625137179820032

Issue manually filed by: msrchandra

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Components: Blink>Layout

Comment 2 by e...@chromium.org, Sep 8 2016

Components: Blink>Editing
Labels: -Pri-1 Pri-2

Comment 3 by yosin@chromium.org, Sep 12 2016

Status: Available (was: Untriaged)

Comment 4 by yosin@chromium.org, Sep 12 2016

crrev.com/1958093002 will fix this issue.
Project Member

Comment 5 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Cc: msrchandra@chromium.org
Labels: Test-Predator-Wrong
Owner: yoichio@chromium.org
Status: Assigned (was: Available)
Find it did not provide any possible suspect.
From the CL, assigning to the concern owner --
https://chromium.googlesource.com/chromium/src/+log/1ae814d2d836ea64a076b0a6d193d83098e812d4..3644e8c55d11a9b4693aa20001b116cdbca266e2?pretty=fuller

Suspecting Commit#
https://chromium.googlesource.com/chromium/src/+/e4edfb63d1b068c5ab5dc6b91edf75c108ebc433

@yoichio -- Could you please look into the issue, kindly re-assign if this is not related to your changes.
Thank You.

Comment 7 by yosin@chromium.org, Feb 25 2017

Components: -Blink>Layout -Blink>Editing Blink>Editing>Selection
Status: WontFix (was: Assigned)
CaretBase (now called CaretDisplayItem) doesn't have this CHECK.

Sign in to add a comment