New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 691338 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 691205
Owner:
NOT IN USE
Closed: Feb 2017
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Regression



Sign in to add a comment

Crash in blink::LayoutMultiColumnSet::newFragmentainerGroupsAllowed

Project Member Reported by ClusterFuzz, Feb 12 2017

Issue description

Cc: haraken@chromium.org nyerramilli@chromium.org
Labels: -Type-Bug Test-Predator-Wrong-CLs M-58 Type-Bug-Regression
Owner: msten...@opera.com
Status: Assigned (was: Untriaged)
Findit did not find any culprit results,

assigning to /src/third_party/WebKit/Source/core/OWNERS, requesting to check the issue and help.

Comment 2 by msten...@opera.com, Feb 13 2017

There's a bunch of assertion failures before the crash. Attaching a minimal test case (which also runs into a few assertion failures before it crashes).
tc.html
339 bytes View Download

Comment 3 by msten...@opera.com, Feb 13 2017

Cc: cbiesin...@chromium.org msten...@opera.com dsinclair@chromium.org
 Issue 691411  has been merged into this issue.

Comment 4 by msten...@opera.com, Feb 13 2017

Caused by https://codereview.chromium.org/2685113002 "Cleanup SVGElement::layoutObjectIsNeeded."

Comment 5 by msten...@opera.com, Feb 13 2017

Mergedinto: 691205
Status: Duplicate (was: Assigned)
Project Member

Comment 6 by ClusterFuzz, Feb 14 2017

ClusterFuzz has detected this issue as fixed in range 449941:449972.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6330276168073216

Fuzzer: bj_broddelwerk
Job Type: linux_asan_chrome_v8_arm
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000ac
Crash State:
  blink::LayoutMultiColumnSet::newFragmentainerGroupsAllowed
  blink::LayoutMultiColumnFlowThread::appendNewFragmentainerGroupIfNeeded
  blink::LayoutMultiColumnFlowThread::layoutColumns
  
Sanitizer: address (ASAN)

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=449604:449634
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=449941:449972

Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv95a6v9BnLZeaMDqn-OkwTVF6jPAUCdNNARzf3cGqDXgcBGK85z_nFA8gcXfPUcGT1JPZOju83ETCqvtFiPk-yZLky2s_laBgUateKZtv3fDW3FbP4hDlz8g7l3xIvOZlEuW4huDJ-hGESYsKxVFUaDY8jivRkyYr3aLWUMhftsf4S-0X8WMzDdengcKpFL9ITe1DP07AfuGqpeysmQ8W6h5596celJM2BWrr8VNeKnLF8UHb-IcLFGJMGjc-FC_XmbJKas4Fjp-LyM-KyDlt6EjEqMyJpOa9e9VGGDyA9XmYP4-dTYNP8EFNYBauvTWpCpVBj6K88jdoznwkbN9sxsLpKtAD0GPck5ID2uX4qtVtL20WXAHuSItQg8m8RN2DRREhdwnHwxjhQMsY3q2YgWl5ZgtMA?testcase_id=6330276168073216


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Sign in to add a comment