!std::isnan(static_cast<double>(value)) in MathExtras.h |
||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5436619739103232 Fuzzer: inferno_layout_test_unmodified Job Type: linux_debug_content_shell_drt Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: !std::isnan(static_cast<double>(value)) in MathExtras.h clampTo<> blink::flooredIntPoint Sanitizer: address (ASAN) Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_debug_content_shell_drt&range=439396:439418 Minimized Testcase (0.57 Kb): https://cluster-fuzz.appspot.com/download/AMIfv962Ptzmh6S00gYeBCoUTr9pqQ0iQn12_hFX7zfueF08-dUeJIyL4YdvU3ft7TyxHGPC4ewY5Iydh8vOj7sFeAD_8IuTUaXfMGuGDBuKjguPEjWjBYDxVnToHIZtiFC6QlDZixGQtYjc6m6Usz_a9VWqjriWd0ihPUbPgjgOQdtbwJ5zIURoRPlEWRCrhIfRMysU9D-JeZqjopwD-nTAImnL7upqqkN463rAgGgeTjj5v0DKFf9eStl-9OEsvG_qBmpUIDsHqEJ1ndFuZAwmVCQmlOWXXEJktxTN70lM-4cp4o6eXKvG9kKCAibOjnUMfS-PsQgg3Rt_NerUOm213nfRbElBFQ9YXiD-rRJ1AADh_c24-3Y?testcase_id=5436619739103232 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jan 25 2017
Able to repro without animations:
<style>
* { transform: scale(401097138271278291218014369784239731996273651907446632432050481860968837260646849527963905321140416504885948851035728884554668596377381844301691779646212276883999347210107904321400853234770400262630966685414177300637226084969485531323928171747339097329680466618459981653096907825383901203435465119229388903918693402127369724991051786999555709460879796564837102452367628787119790434501380107047836355838879441103978499945667529484302237233525892600799265138305038712034566566617672453247882237070896, 5); }
</style>
,
Mar 16 2017
,
Mar 29 2017
Using Code Search for the file, "MathExtras.h", assigning to the concern owner. Suspecting Commit# https://chromium.googlesource.com/chromium/src/+/b37bdbd63ea254bbaaab5e1094cbe37c441f4bb2 @ricea -- Could you please look into the issue, kindly re-assign if this is not related to your changes. Thank You.
,
Mar 30 2017
Need a proper debug build to get line information, but based on a stack trace from a release build and a bit of code search and imagination, the problem appears to be this line in third_party/WebKit/Source/core/layout/LayoutGeometryMap.cpp:
ASSERT(enclosingIntRect(layoutObjectMappedResult) ==
enclosingIntRect(result.boundingBox()) ||
layoutObjectMappedResult.mayNotHaveExactIntRectRepresentation() ||
result.boundingBox().mayNotHaveExactIntRectRepresentation());
As such, assigning chrishtr@ who last tried to fix this assert.
,
Apr 7 2017
,
Jul 30 2017
Detailed report: https://clusterfuzz.com/testcase?key=6464587770888192 Job Type: linux_debug_content_shell_drt Crash Type: CHECK failure Crash Address: Crash State: !std::isnan(static_cast<double>(value)) in MathExtras.h int clampTo<int, float> blink::FlooredIntPoint Sanitizer: address (ASAN) Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6464587770888192 See https://github.com/google/clusterfuzz-tools for more information.
,
Jul 31
This issue has been Available for over a year. If it's no longer important or seems unlikely to be fixed, please consider closing it out. If it is important, please re-triage the issue. Sorry for the inconvenience if the bug really should have been left as Available. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Aug 1
,
Aug 6
|
||||||||||
►
Sign in to add a comment |
||||||||||
Comment 1 by tkent@chromium.org
, Jan 24 2017