Crash in blink::FramePainter::paintScrollCorner |
|||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5702718305075200 Fuzzer: inferno_twister Job Type: windows_syzyasan_content_shell Platform Id: windows Crash Type: UNKNOWN Crash Address: 0x00000003 Crash State: blink::FramePainter::paintScrollCorner blink::PaintLayerCompositor::paintContents blink::GraphicsLayer::paintWithoutCommit Memory Tool: SYZYASAN Regressed: https://clusterfuzz.com/revisions?job=windows_syzyasan_content_shell&range=456508:456580 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv97-vPK7A3k03GTXVONnA3EtjKhAgpjrQaZBHcBwVOHqDLaee5fuqSRCKX80ETWZLrIs_meaGoZJ1H32UokVV12p_lu7B8N6aqZp3CmgTkvdOeyerFWzVa1QKAfh4tY0Nuqy_n59NH2PdszOvC_Ui71DhQXD_mnQF1FQUly4uHhEGX11aaVdJcpBy2nItam81E2bNDoPnZa4yo1Jw8rOqb9bbo_Fxz_KTPh71YHEsusX_WdpoSWuVL1LkMmqbwjJMeAN23GNtLf9qqsAi7oXvYj8OjZSkHjbXJrx_xpSUKmJdJLf04U3DfqHZQxzBI12EUhyvyMz7lPPi6QiEjJSnoimyGxRuWtfPkEPUQbcM93FYEe3cCAKQ2e1H26tfQEPf2lUvOl0mlaRnE2eVOkDSiM-LwDXHQ?testcase_id=5702718305075200 Additional requirements: Requires HTTP Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 18 2017
,
Apr 18 2017
The test case is using an internals method that we don' ship so there isn't harm to users. Downgrading priority somewhat because of that but we should still look into it. I think the bug is that we're keeping around a GraphicsLayer for the scroll corner when no scrollbars exist. The scroll corner should have been destroyed when we "adjusted scrollbar existence" in FrameView.
,
Apr 19 2017
,
Apr 19 2017
Can not reproduce this issue on latest Window asan build. Tried open the the page (via http server) on Chrome and run in content_shell (w/o --run-layout-test).
,
Apr 19 2017
It requires internals, did you remember to add --expose-internals-for-testing? Did you try using --run-layout-test?
,
Apr 19 2017
Tried --run-layout-test.
,
Apr 20 2017
ClusterFuzz has detected this issue as fixed in range 465765:465806. Detailed report: https://clusterfuzz.com/testcase?key=5702718305075200 Fuzzer: inferno_twister Job Type: windows_syzyasan_content_shell Platform Id: windows Crash Type: UNKNOWN Crash Address: 0x00000003 Crash State: blink::FramePainter::paintScrollCorner blink::PaintLayerCompositor::paintContents blink::GraphicsLayer::paintWithoutCommit Memory Tool: SYZYASAN Regressed: https://clusterfuzz.com/revisions?job=windows_syzyasan_content_shell&range=456508:456580 Fixed: https://clusterfuzz.com/revisions?job=windows_syzyasan_content_shell&range=465765:465806 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv97-vPK7A3k03GTXVONnA3EtjKhAgpjrQaZBHcBwVOHqDLaee5fuqSRCKX80ETWZLrIs_meaGoZJ1H32UokVV12p_lu7B8N6aqZp3CmgTkvdOeyerFWzVa1QKAfh4tY0Nuqy_n59NH2PdszOvC_Ui71DhQXD_mnQF1FQUly4uHhEGX11aaVdJcpBy2nItam81E2bNDoPnZa4yo1Jw8rOqb9bbo_Fxz_KTPh71YHEsusX_WdpoSWuVL1LkMmqbwjJMeAN23GNtLf9qqsAi7oXvYj8OjZSkHjbXJrx_xpSUKmJdJLf04U3DfqHZQxzBI12EUhyvyMz7lPPi6QiEjJSnoimyGxRuWtfPkEPUQbcM93FYEe3cCAKQ2e1H26tfQEPf2lUvOl0mlaRnE2eVOkDSiM-LwDXHQ?testcase_id=5702718305075200 Additional requirements: Requires HTTP See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Apr 20 2017
ClusterFuzz testcase 5702718305075200 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Apr 20 2017
Hah, great work Chao! :P |
|||||
►
Sign in to add a comment |
|||||
Comment 1 by msrchandra@chromium.org
, Apr 18 2017Components: Blink>Paint
Labels: M-60 Test-Predator-Correct-CLs
Owner: chaopeng@chromium.org
Status: Assigned (was: Untriaged)