Issue metadata
Sign in to add a comment
|
false. Can't find cached display item in PaintController.cpp |
||||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5480025644335104 Fuzzer: mbarbella_js_mutation_layout Job Type: linux_ubsan_vptr_content_shell_drt Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: false. Can't find cached display item in PaintController.cpp blink::PaintController::findOutOfOrderCachedItemForward blink::PaintController::useCachedDrawingIfPossible Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_vptr_content_shell_drt&range=416257:416283 Minimized Testcase (0.90 Kb): https://cluster-fuzz.appspot.com/download/AMIfv957PtoMC20k6qRKYgCIP0ub-lbjUfO0D8fhS7UUxOz3_k38eeus_iTx-ecgyeiR0CuWKVXW6dR_uS5JMCKJcoa-vl0QwtPVLGaIA_NSBfRlvIVURgzbAJlpgUdRhX-99Jky-qjpACQRq6ln3h4g7b5g53ORtg?testcase_id=5480025644335104 Issue manually filed by: nyerramilli See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Oct 12 2016
,
Oct 18 2016
,
Oct 19 2016
,
Nov 5 2016
ClusterFuzz has detected this issue as fixed in range 429839:429962. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5480025644335104 Fuzzer: mbarbella_js_mutation_layout Job Type: linux_ubsan_vptr_content_shell_drt Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: false. Can't find cached display item in PaintController.cpp blink::PaintController::findOutOfOrderCachedItemForward blink::PaintController::useCachedDrawingIfPossible Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_vptr_content_shell_drt&range=416257:416283 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_vptr_content_shell_drt&range=429839:429962 Minimized Testcase (0.90 Kb): https://cluster-fuzz.appspot.com/download/AMIfv957PtoMC20k6qRKYgCIP0ub-lbjUfO0D8fhS7UUxOz3_k38eeus_iTx-ecgyeiR0CuWKVXW6dR_uS5JMCKJcoa-vl0QwtPVLGaIA_NSBfRlvIVURgzbAJlpgUdRhX-99Jky-qjpACQRq6ln3h4g7b5g53ORtg?testcase_id=5480025644335104 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by nyerramilli@chromium.org
, Oct 12 2016Components: Tools>Test>FindIt>NoResult
Labels: findit-wrong Te-Logged
Owner: wangxianzhu@chromium.org
Status: Assigned (was: Untriaged)