document().body() != refChild in CompositeEditCommand.cpp |
|||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5563205416124416 Fuzzer: mbarbella_js_mutation_layout Job Type: linux_debug_content_shell_drt Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: document().body() != refChild in CompositeEditCommand.cpp blink::CompositeEditCommand::insertNodeBefore blink::CompositeEditCommand::insertNodeAfter Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=369991:370003 Minimized Testcase (0.38 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv95nrW3imvWz3pEQMPM16L72pA6anAF7OTHbeoHpXmiI-GMHH4N_FqTtFXo10tB8s_l07EWPE07Qqp1q4XkjBhurNQFYZfpmJEf9VJHrFheYePQFrptjdELNRLA1nRHft9AUkOOd-DsTwtDIL8WOJVz8atrNbA?testcase_id=5563205416124416 <style> p.red { background-color: red;</style> testRunner.dumpAsTextWithPixelResults(); <br/> <style> * { display: -webkit-inline-box; } .CLASS11 { float: right;</style> <script> window.onload = function () { document.designMode = 'on'; document.execCommand('SelectAll') document.execCommand('Indent'); }; </script> <div class="CLASS11"> </div> bbb Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Nov 18 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Nov 30 2016
,
Mar 15 2017
Looking
,
Mar 16 2017
,
Mar 16 2017
,
Mar 27 2017
,
Mar 27 2017
Mark this Pri-2 because the reproduction has unusual style, "* { display: -webkit-inline-box; }" and we don't think this issue is practical.
,
May 22 2017
Bulk set to Pri-3 for cluster fuzz bugs. Since these issues are happens with unusual HTML.
,
Jun 21 2017
ClusterFuzz testcase 5563205416124416 is flaky and no longer reproduces, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
|||||||||||
►
Sign in to add a comment |
|||||||||||
Comment 1 by mmohammad@chromium.org
, Oct 19 2016Owner: ojan@chromium.org
Status: Assigned (was: Untriaged)