New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 662222 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Dec 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

containerA in EditingUtilities.cpp

Project Member Reported by ClusterFuzz, Nov 3 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5579012040818688

Fuzzer: bj_broddelwerk
Job Type: linux_debug_chrome
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  containerA in EditingUtilities.cpp
  blink::comparePositions<>
  blink::comparePositionsInFlatTree
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_chrome&range=388139:388165

Minimized Testcase (2.10 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95PA5Squd_--ifWhJLA01M23eWEt_0z6m8F2r6pbYX5TtoMfSR1Mt2d7DEz-lKSoGyrOKFwnBWdXC1x7wjDbYCfkmDuycdWDG-N-1SS2X97Fr6RxniB4N8owG7-ETEuPWVN-ZZKu-vWYXVmfwmExN9DYilcwQ?testcase_id=5579012040818688

Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Labels: Test-Predator-Wrong
Cc: msrchandra@chromium.org koten...@yandex-team.ru
No successful results from Find it,
Suspected CLs	Findit could not determine the memory tool from the stacktrace. Is it in a new format?

From the regressed CL, assigning it to the concern owner,
https://chromium.googlesource.com/chromium/src/+log/cbafec61cd191c38e0d8a16a0bd5bd8c87a437fa..2d8b210dffbc41e44addc6a6c16a507d5de171a0?pretty=fuller

Suspected Commit# 4021ae18b9410d496adc92077e00672253f3876d	
Suspected Review URL# https://codereview.chromium.org/1878473002

@kotenkov -- Could you please look into the issue, kindly assign to the concern owner if this might not related to your change.
Yhank You.
Cc: yosin@chromium.org
Since my commit is just an ASSERT -> DCHECK conversion, I don't think it is the reason of the crash. 
Cc-ing yosin as a proper owner.
Components: Blink>Editing
Labels: -Test-Predator-Wrong Test-Predator-Wrong-CLs
Labels: M-55
Owner: xiaoche...@chromium.org
Status: Assigned (was: Untriaged)
Possible suspect is:
https://codereview.chromium.org/2392473002
xiaochengh@, could you please take a look and help us to find correct owner if it is not related your changes.
The CL in #6 is irrelevant.

DOM tree at crash site:

#document
  HTML (focused)
    ...
    OPTION
      #shadow-root
      SELECT
        #shadow-root
	        CONTENT
      ...

It seems to be due to an undo step stores an ending selection that's not in the flat tree: [SELECT@beforeAnchor, SELECT@afterAnchor]. Then we get into trouble when trying to set the FrameSelection to this non-null but actually null selection.

Comment 8 by yosin@chromium.org, Nov 10 2016

Cc: -yosin@chromium.org
Labels: -Pri-1 Pri-2
Status: Started (was: Assigned)
Lower to pri-2 since reald world usage of insertOrderedList is low and it caused by unusual HTML

http://crrev.com/1958093002 will fix this.
Project Member

Comment 9 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 10 by ClusterFuzz, Dec 1 2016

ClusterFuzz has detected this issue as fixed in range 435159:435196.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5579012040818688

Fuzzer: bj_broddelwerk
Job Type: linux_debug_chrome
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  containerA in EditingUtilities.cpp
  blink::comparePositions<>
  blink::comparePositionsInFlatTree
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_chrome&range=388139:388165
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_chrome&range=435159:435196

Minimized Testcase (2.10 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95PA5Squd_--ifWhJLA01M23eWEt_0z6m8F2r6pbYX5TtoMfSR1Mt2d7DEz-lKSoGyrOKFwnBWdXC1x7wjDbYCfkmDuycdWDG-N-1SS2X97Fr6RxniB4N8owG7-ETEuPWVN-ZZKu-vWYXVmfwmExN9DYilcwQ?testcase_id=5579012040818688

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Status: Fixed (was: Started)
Seems fixed by yosin@'s r435191.

Sign in to add a comment