Crash in blink::PrePaintTreeWalk::Walk |
|||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5415251999981568 Fuzzer: miaubiz_svg_fuzzer Job Type: windows_asan_chrome Platform Id: windows Crash Type: UNKNOWN READ Crash Address: 0x00000000 Crash State: blink::PrePaintTreeWalk::Walk blink::PrePaintTreeWalk::Walk blink::PrePaintTreeWalk::Walk Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=windows_asan_chrome&range=464127:464504 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv95OrNioAp5OTDDxSxxcCX2gGYIDT8nt1T47erLwXpPZghpv4CKWPG6yRM6MDnJfOITQJvFq_-2F-0cxH_JdxifB32ExzAxqINe8dVGJy0XL2qa96jWPRbv4x6mf_MBNpAjhVgJstkV8i1tke7ey8R2ptmXHqFKbNOj1oX9AMyU7V3kmFe8dQgWpre9d3MNAL49ArMAGzfJebNQDhglQO1_HYcSQftP6qvNqRX4f8Dcsbv1M5AsOFxznBs96RSEhL-8xxZbQjV5pGwg5xGLcs9KvzC7o6yHJBIZ_c3QDWDc9hJlG90YqC-4qIVfyTz288bxuVezdfX7SHapUCYYlxqhd89t5iukBhi5A2058FGZBC4VUHs8?testcase_id=5415251999981568 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 20 2017
,
Apr 20 2017
This is mine. Might have been fixed.
,
Apr 20 2017
Issue 712985 has been merged into this issue.
,
Apr 20 2017
,
Apr 20 2017
This is not fixed. Manually reduced test case:
,
Apr 20 2017
,
Apr 21 2017
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/e715cb02c568dc66f7a6db7b216c616ae22d7017 commit e715cb02c568dc66f7a6db7b216c616ae22d7017 Author: wangxianzhu <wangxianzhu@chromium.org> Date: Fri Apr 21 00:02:51 2017 Fix LayoutObject::SetSubtreeNeedsPaintPropertyUpdate() to set ancestor flags BUG= 713503 Review-Url: https://codereview.chromium.org/2831203002 Cr-Commit-Position: refs/heads/master@{#466194} [modify] https://crrev.com/e715cb02c568dc66f7a6db7b216c616ae22d7017/third_party/WebKit/Source/core/dom/DocumentLifecycle.cpp [modify] https://crrev.com/e715cb02c568dc66f7a6db7b216c616ae22d7017/third_party/WebKit/Source/core/layout/LayoutObject.h [modify] https://crrev.com/e715cb02c568dc66f7a6db7b216c616ae22d7017/third_party/WebKit/Source/core/layout/LayoutObjectTest.cpp
,
Apr 21 2017
,
Apr 21 2017
ClusterFuzz has detected this issue as fixed in range 466183:466203. Detailed report: https://clusterfuzz.com/testcase?key=5415251999981568 Fuzzer: miaubiz_svg_fuzzer Job Type: windows_asan_chrome Platform Id: windows Crash Type: UNKNOWN READ Crash Address: 0x00000000 Crash State: blink::PrePaintTreeWalk::Walk blink::PrePaintTreeWalk::Walk blink::PrePaintTreeWalk::Walk Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=windows_asan_chrome&range=464127:464504 Fixed: https://clusterfuzz.com/revisions?job=windows_asan_chrome&range=466183:466203 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv94a-eLZC6-bBxamjyQwlLoWyz_ANi1GuzbmcZJpnVsHi3c-XE50KWTfT1p-x2wapAMNs6bTyotnwMlzPDNJ-mgw3nCCgfRHv18RkKt5-cB38DJ7aLXvhUQFkqy_llV5vAbTmZDn1DgluUjMSm4S6Kqng05TLhRQIEpY1GKauERap5GOshbcuEPhct8VoNwr26SjwYu3GLNn8XeaypoJvEbKOe_l_ru0at6aNeeyEGddZ_rAK673jIS4JbX6b8R01UdB3IH5q4S-bf-8qqM_j1oCKrBsXtmh_3rf0p-euy2m5Rk7MNu-oq-5t8675F7twBYfKLeHjWiQXqKSBBensGSzhl3KK2Kuj_dC0yVJCRHTUWzd1Rk?testcase_id=5415251999981568 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Apr 21 2017
ClusterFuzz testcase 5415251999981568 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Apr 22 2017
Your change meets the bar and is auto-approved for M59. Please go ahead and merge the CL to branch 3071 manually. Please contact milestone owner if you have questions. Owners: amineer@(Android), cmasso@(iOS), gkihumba@(ChromeOS), Abdul Syed@(Desktop) For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Apr 22 2017
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/0fc7773682fc99248d9ae044ffbde6aafd7f25ec commit 0fc7773682fc99248d9ae044ffbde6aafd7f25ec Author: wangxianzhu <wangxianzhu@chromium.org> Date: Sat Apr 22 03:43:40 2017 Fix LayoutObject::SetSubtreeNeedsPaintPropertyUpdate() to set ancestor flags BUG= 713503 Review-Url: https://codereview.chromium.org/2831203002 Cr-Commit-Position: refs/heads/master@{#466194} TBR=wangxianzhu@chromium.org NOTRY=true NOPRESUBMIT=true Review-Url: https://codereview.chromium.org/2839463002 Cr-Commit-Position: refs/branch-heads/3071@{#142} Cr-Branched-From: a106f0abbf69dad349d4aaf4bcc4f5d376dd2377-refs/heads/master@{#464641} [modify] https://crrev.com/0fc7773682fc99248d9ae044ffbde6aafd7f25ec/third_party/WebKit/Source/core/dom/DocumentLifecycle.cpp [modify] https://crrev.com/0fc7773682fc99248d9ae044ffbde6aafd7f25ec/third_party/WebKit/Source/core/layout/LayoutObject.h [modify] https://crrev.com/0fc7773682fc99248d9ae044ffbde6aafd7f25ec/third_party/WebKit/Source/core/layout/LayoutObjectTest.cpp |
|||||||||
►
Sign in to add a comment |
|||||||||
Comment 1 by msrchandra@chromium.org
, Apr 20 2017Components: Blink>Paint
Labels: M-60 Test-Predator-Correct-CLs
Owner: joelhockey@chromium.org
Status: Assigned (was: Untriaged)