Crash in GetTreeScope |
||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=6107450209206272 Fuzzer: bj_broddelwerk Job Type: linux_lsan_chrome_mp Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000020 Crash State: GetTreeScope ShadowDepthOf<blink::EditingAlgorithm<blink::NodeTraversal> blink::TextIteratorAlgorithm<blink::EditingAlgorithm<blink::NodeTraversal> >::In Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=linux_lsan_chrome_mp&range=209699:209703 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6107450209206272 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
May 3 2017
I was able to reproduce with content_shell on Linux. Got [1:1:0503/115819.551640:1998824677082:FATAL:CompositeEditCommand.cpp(1472)] Check failed: destination.DeepEquivalent().IsConnected(). SELECT class="CLASS2"@afterAnchor/TextAffinity::Downstream After I removed DCHECKs eventually I get the null |end_container| in TextIteratorAlgorithm<Strategy>::Initialize() https://cs.chromium.org/chromium/src/third_party/WebKit/Source/core/editing/iterators/TextIterator.cpp?rcl=f7c0e7db6402fdb3ca65b7e6ffa44989ee056c13&l=245 and the crash.
,
May 3 2017
I reverted my CL and got the same behavior. So probably it is not it.
,
May 12 2017
Re-doing the task as there is no regression issue, will update once the regression range is fetched. Thank You.
,
Jun 11 2017
ClusterFuzz testcase 6107450209206272 is flaky and no longer reproduces, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||||
►
Sign in to add a comment |
||||
Comment 1 by msrchandra@chromium.org
, May 3 2017Labels: Test-Predator-Wrong M-59
Owner: ti...@chromium.org
Status: Assigned (was: Untriaged)