Issue metadata
Sign in to add a comment
|
m_width.fitsOnLine(rect.width() - 1) in BreakingContextInlineHeaders.h |
||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5290183006355456 Fuzzer: inferno_twister Job Type: linux_debug_content_shell_drt Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: m_width.fitsOnLine(rect.width() - 1) in BreakingContextInlineHeaders.h blink::BreakingContext::rewindToMidWordBreak blink::BreakingContext::handleText Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=393279:393304 Minimized Testcase (0.10 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv96NCPlTxz7TTCGYZUtfGp5be933pPtudtrhbd012wdRY0kVO4ZdDsaxks0ug-WygbRrtjwa8rr4xvTZhhZvTSQP62FJQnxXaYPZA7eTq0JTX2SNHqV_WaVMvhxxr0wli8QLA6lgHXfpgk1xeUeFvgUXN8InDg?testcase_id=5290183006355456 <div contenteditable="">S d9r~I<span>drag<style> * { shape-rendering: optimizeQuality; font-size: 28rem; Issue manually filed by: nyerramilli See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Oct 17 2016
Given the previous fix still leaves some other cases for this to fire, and given this DCHECK isn't as fatal as I thought when I put it, I prefer to remove the DCHECK.
,
Oct 17 2016
Sorry for late reply. Then, I'm not authorized to access the detailed report and minimized testcase. @kojii, I'm not sure about the text-layout, But, even if the DCHECK is not fatal, there are wrong text-layout in that case, right?
,
Oct 18 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/7063f99d4a6ae1b57d47d012b4e53c57f25187d6 commit 7063f99d4a6ae1b57d47d012b4e53c57f25187d6 Author: kojii <kojii@chromium.org> Date: Tue Oct 18 01:20:27 2016 Remove DCHECK in BreakingContextInlineHeader that wasn't much useful Originally thought this failure can lead to layout failures, but as we understand failing cases, its failure does not look to cause any real problems. BUG= 655067 Review-Url: https://codereview.chromium.org/2425593002 Cr-Commit-Position: refs/heads/master@{#425845} [modify] https://crrev.com/7063f99d4a6ae1b57d47d012b4e53c57f25187d6/third_party/WebKit/Source/core/layout/line/BreakingContextInlineHeaders.h
,
Oct 18 2016
,
Oct 18 2016
,
Oct 19 2016
ClusterFuzz has detected this issue as fixed in range 425834:425887. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5290183006355456 Fuzzer: inferno_twister Job Type: linux_debug_content_shell_drt Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: m_width.fitsOnLine(rect.width() - 1) in BreakingContextInlineHeaders.h blink::BreakingContext::rewindToMidWordBreak blink::BreakingContext::handleText Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=393279:393304 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=425834:425887 Minimized Testcase (0.10 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv96NCPlTxz7TTCGYZUtfGp5be933pPtudtrhbd012wdRY0kVO4ZdDsaxks0ug-WygbRrtjwa8rr4xvTZhhZvTSQP62FJQnxXaYPZA7eTq0JTX2SNHqV_WaVMvhxxr0wli8QLA6lgHXfpgk1xeUeFvgUXN8InDg?testcase_id=5290183006355456 <div contenteditable="">S d9r~I<span>drag<style> * { shape-rendering: optimizeQuality; font-size: 28rem; See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by nyerramilli@chromium.org
, Oct 12 2016Components: Tools>Test>FindIt>NoResult
Labels: -Pri-1 -Type-Bug findit-wrong Te-Logged Pri-2 Type-Bug-Regression
Owner: kojii@chromium.org
Status: Assigned (was: Untriaged)