Crash in blink::SubtreeLayoutScope::SubtreeLayoutScope |
||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5174274672558080 Fuzzer: inferno_webbot Job Type: windows_asan_chrome Platform Id: windows Crash Type: UNKNOWN READ Crash Address: 0x00000000 Crash State: blink::SubtreeLayoutScope::SubtreeLayoutScope blink::LayoutView::UpdateLayout blink::FrameView::PerformLayout Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=windows_asan_chrome&range=458565:458598 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv96UjVkzwbA9V8grkYpCve9BsD66YstBvhMAVKUeUB36cU7qSKxLyP-8cyI2MGGUQStgSD_h7ZWgmGIgEFw2bdIie6Jtg5Bs449QTrBnzQfDpIWTrAe-28yN6H0TEuPYR6boUtzI1lR2oFrpb-crqu5HKeld_M9daxmzdQrn2rCnLmM25bD33Mb2zRE3Lw9lYKH8EqXk_i5ZyUOhFxZxF79u9Mb6dBzSbK3F8uNGyxFUHhIZeDUigE3pS1MIYXf5PlfJxTRKalYH0GCjLo6ZRqCW6FOEIIQIJZypokWBIlhib8wzUfr62ARjP_ni1vjQj7wTQMTrEyKyx5oyRJ8ataWzVlyKASPS1OQLBFMr1xXqs5nbYm0?testcase_id=5174274672558080 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 20 2017
esprehn: Could you PTAL or reassign to somebody more familiar than me with Blink>Layout component? msrchandra: The CL from #c1 is the Big Blink Rename - it shows up in git blame almost everywhere but is not (should not be) responsible for any behavior changes. I guess this should give me an extra push to look at issue 584560 :-)
,
Apr 20 2017
This is a nullptr crash, someone on the layout team should handle it. Note that if you don't assign things and leave them in the >Layout component their normal bug triage process should handle it.
,
Apr 21 2017
Possibly related to 709996.
,
Apr 21 2017
Issue 709996 has been merged into this issue.
,
Apr 21 2017
Users experienced this crash on the following builds: Win Canary 60.0.3074.0 - 0.21 CPM, 10 reports, 10 clients (signature blink::SubtreeLayoutScope::SubtreeLayoutScope) If this update was incorrect, please add "Fracas-Wrong" label to prevent future updates. - Go/Fracas
,
Apr 21 2017
I have not been able to reproduce this.
,
Apr 22 2017
Users experienced this crash on the following builds: Win Dev 59.0.3071.15 - 0.19 CPM, 11 reports, 11 clients (signature blink::SubtreeLayoutScope::SubtreeLayoutScope) If this update was incorrect, please add "Fracas-Wrong" label to prevent future updates. - Go/Fracas
,
Apr 29 2017
This crash has high impact on Chrome's stability. Signature: blink::SubtreeLayoutScope::SubtreeLayoutScope. Channel: canary. Platform: win. Labeling issue 713452 with ReleaseBlock-Dev. If this update was incorrect, please add "Fracas-Wrong" label to prevent future updates. - Go/Fracas
,
May 1 2017
Clusterfuzz no longer considers this a security issue and can't reproduce it anymore. Also failed to reproduce it manually. Closing. |
||||||||
►
Sign in to add a comment |
||||||||
Comment 1 by msrchandra@chromium.org
, Apr 20 2017Components: Blink>Layout
Labels: Test-Predator-Wrong-CLs M-60
Owner: lukasza@chromium.org
Status: Assigned (was: Untriaged)