CHECK failure: list_node in LayoutListItem.cpp |
|||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5629767765458944 Fuzzer: inferno_layout_test_unmodified Job Type: linux_asan_chrome_mp Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: list_node in LayoutListItem.cpp blink::LayoutListItem::UpdateListMarkerNumbers blink::LayoutObjectChildList::RemoveChildNode Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_mp&range=467230:467252 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5629767765458944 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 26 2017
,
May 1 2017
,
May 1 2017
,
May 1 2017
Intentional crash for corrupted content. Ideally we should detect this before we get into a bad state but given lack of reports in the wild and the hoops required to get into a bad state it isn't a priority at the moment.
,
May 14 2017
,
May 17 2017
,
May 22 2017
Issue 724865 has been merged into this issue.
,
May 22 2017
there is a repro for this in issue 724865
,
Jul 20 2017
ClusterFuzz has detected this issue as fixed in range 488064:488102. Detailed report: https://clusterfuzz.com/testcase?key=5629767765458944 Fuzzer: inferno_layout_test_unmodified Job Type: linux_asan_chrome_mp Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: list_node in LayoutListItem.cpp blink::LayoutListItem::UpdateListMarkerNumbers blink::LayoutObjectChildList::RemoveChildNode Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_mp&range=467230:467252 Fixed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_mp&range=488064:488102 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5629767765458944 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jul 20 2017
ClusterFuzz testcase 5629767765458944 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Jul 27 2017
ClusterFuzz testcase 5874972991160320 is still reproducing on tip-of-tree build (trunk). Please re-test your fix against this testcase and if the fix was incorrect or incomplete, please re-open the bug. Otherwise, ignore this notification and add ClusterFuzz-Wrong label. |
|||||||||
►
Sign in to add a comment |
|||||||||
Comment 1 by msrchandra@chromium.org
, Apr 26 2017Labels: M-60 Test-Predator-Wrong
Owner: e...@chromium.org
Status: Assigned (was: Untriaged)