CHECK failure: false in PaintController.cpp |
||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=6146499355607040 Fuzzer: mbarbella_js_mutation_layout Job Type: linux_asan_content_shell_drt Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: false in PaintController.cpp blink::PaintController::EndSubsequence blink::PaintLayerPainter::PaintLayerContents Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=linux_asan_content_shell_drt&range=419848:419971 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6146499355607040 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Aug 16 2017
,
Aug 31 2017
Actual minimized case. This is an under-invalidation bug. To reproduce, run content_hell --run-layout-test with the attached file. There are no security or crash implications of this bug, so removed those labels.
,
Sep 11 2017
,
Sep 12 2017
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/bb0f9dfbaeceba296cbc055b9dee797d902136e2 commit bb0f9dfbaeceba296cbc055b9dee797d902136e2 Author: Xianzhu Wang <wangxianzhu@chromium.org> Date: Tue Sep 12 02:49:42 2017 Fix false-positive of under-invalidation checking If a subsequence was fully painted the last time, we don't repaint the subsequence on interest rect change because the fully painted result is still useable. However this triggers false-positive of under- invalidation checking which strictly matches new and cached subsequences. Bug: 755478 Cq-Include-Trybots: master.tryserver.chromium.linux:linux_layout_tests_slimming_paint_v2 Change-Id: I24f8fa9c2e3167ff3c54954bf5e994a74ef70056 Reviewed-on: https://chromium-review.googlesource.com/661379 Commit-Queue: Xianzhu Wang <wangxianzhu@chromium.org> Reviewed-by: Chris Harrelson <chrishtr@chromium.org> Cr-Commit-Position: refs/heads/master@{#501161} [modify] https://crrev.com/bb0f9dfbaeceba296cbc055b9dee797d902136e2/third_party/WebKit/LayoutTests/FlagExpectations/enable-slimming-paint-v2 [modify] https://crrev.com/bb0f9dfbaeceba296cbc055b9dee797d902136e2/third_party/WebKit/Source/core/paint/PaintLayerPainter.cpp [modify] https://crrev.com/bb0f9dfbaeceba296cbc055b9dee797d902136e2/third_party/WebKit/Source/core/paint/PaintLayerPainterTest.cpp [modify] https://crrev.com/bb0f9dfbaeceba296cbc055b9dee797d902136e2/third_party/WebKit/Source/platform/graphics/paint/PaintController.cpp [modify] https://crrev.com/bb0f9dfbaeceba296cbc055b9dee797d902136e2/third_party/WebKit/Source/platform/graphics/paint/PaintController.h [modify] https://crrev.com/bb0f9dfbaeceba296cbc055b9dee797d902136e2/third_party/WebKit/Source/platform/graphics/paint/PaintControllerTest.cpp
,
Sep 12 2017
,
Sep 12 2017
ClusterFuzz has detected this issue as fixed in range 501156:501180. Detailed report: https://clusterfuzz.com/testcase?key=6146499355607040 Fuzzer: mbarbella_js_mutation_layout Job Type: linux_asan_content_shell_drt Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: false in PaintController.cpp blink::PaintController::EndSubsequence blink::PaintLayerPainter::PaintLayerContents Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=linux_asan_content_shell_drt&range=419848:419971 Fixed: https://clusterfuzz.com/revisions?job=linux_asan_content_shell_drt&range=501156:501180 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6146499355607040 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Sep 12 2017
ClusterFuzz testcase 6146499355607040 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||||||
►
Sign in to add a comment |
||||||
Comment 1 by msrchandra@chromium.org
, Aug 16 2017Components: Blink>Paint
Labels: Test-Predator-Wrong-CLs M-62
Owner: chrishtr@chromium.org
Status: Assigned (was: Untriaged)