New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 729293 link

Starred by 3 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Aug 2017
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Mac
Pri: 1
Type: Bug



Sign in to add a comment

CHECK failure: count <= MaxElementCountInBackingStore<T>() in PartitionAllocator.h

Project Member Reported by ClusterFuzz, Jun 3 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5633313418248192

Fuzzer: inferno_layout_test_unmodified
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: CHECK failure
Crash Address: 
Crash State:
  count <= MaxElementCountInBackingStore<T>() in PartitionAllocator.h
  blink::CSSTokenizer::CSSTokenizer
  blink::CSSParserImpl::ParseStyleSheet
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=447465:447478

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5633313418248192


Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Project Member

Comment 1 by ClusterFuzz, Jun 3 2017

Labels: OS-Linux
Cc: ranjitkan@chromium.org sashab@chromium.org
Labels: M-61 Test-Predator-Wrong
Owner: aazzam@google.com
Status: Assigned (was: Untriaged)
Predator could not generate any suspected CL.

From the regression range below:
https://chromium.googlesource.com/chromium/src/+log/2d184d931166e89d8163c78f945fa168afd080d2..5d6f36b35b6bf8bd4c31f861e5f46875b46fb82d?pretty=fuller

Suspecting the below change could be a possible culprit:
https://chromium.googlesource.com/chromium/src/+/bd564cefdfd28db390dcde233aa9bb5b5943abea

@ aazzam: Assigning to you, kindly take a look into it. Please help us to find an owner if not with respect to your change.

Thanks.!
Project Member

Comment 3 by sheriffbot@chromium.org, Jun 7 2017

Labels: Hotlist-Recharge-BouncingOwner
Owner: ----
Status: Untriaged (was: Assigned)
The assigned owner "aazzam@google.com" is not able to receive e-mails, please re-triage.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 4 by ClusterFuzz, Jun 19 2017

Labels: OS-Windows
Status: WontFix (was: Untriaged)
CF grouping is having issues, closing this so that new one can be filed properly.
Project Member

Comment 6 by ClusterFuzz, Aug 16 2017

Labels: Needs-Feedback
ClusterFuzz testcase 5633313418248192 is still reproducing on tip-of-tree build (trunk).

If this testcase was not reproducible locally or unworkable, ignore this notification and we will file another bug soon with hopefully a better and workable testcase.

Otherwise, if this is not intended to be fixed (e.g. this is an intentional crash), please add ClusterFuzz-Ignore label to prevent future bug filing with similar crash stacktrace.

Sign in to add a comment