New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 758475 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
(currently inactive on Chromium)
Closed: Sep 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Mac
Pri: 1
Type: Bug



Sign in to add a comment

Stack-overflow in blink::LayoutBox::AvailableLogicalHeightUsing

Project Member Reported by ClusterFuzz, Aug 24 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5433233616666624

Fuzzer: bj_broddelwerk
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: Stack-overflow
Crash Address: 0x7fff5d5f9ce0
Crash State:
  blink::LayoutBox::AvailableLogicalHeightUsing
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=405185:405467

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5433233616666624

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 

Comment 1 by tapted@chromium.org, Aug 24 2017

Components: Blink>Layout
Cc: msrchandra@chromium.org sandeepkumars@chromium.org
Labels: Test-Predator-Wrong-CLs M-62
Owner: r...@opera.com
Status: Assigned (was: Untriaged)
Predator and CL could not provide any possible suspects.
Using Code Search for the file, "LayoutBox.cpp" assigning to the concern owner who might be related.

Suspecting Commit#
https://chromium.googlesource.com/chromium/src/+/1fac40c94ca96fc8bac2b00aab7bddc0d3a7b851

@rune -- Could you please look into the issue, kindly re-assign if this is not related to your changes.
Thank You.

Comment 3 by r...@opera.com, Aug 29 2017

Cc: -sandeepkumars@chromium.org r...@opera.com
Owner: sandeepkumars@chromium.org
How could you suspect that commit when it's not in the range reported by clusterfuzz?

Project Member

Comment 4 by ClusterFuzz, Sep 18 2017

Labels: OS-Linux
Owner: ----
Unable to find the suspect from above CL. Hence Changing Status to Untriaged.

Thanks!!
Status: Untriaged (was: Assigned)
Cc: kkaluri@chromium.org
Labels: -Test-Predator-Wrong-CLs Test-Predator-Correct-CLs
Owner: ymalik@chromium.org
Status: Assigned (was: Untriaged)
Predator did provide some possible suspects.
Using Search for the file, "LayoutBox.cpp" assigning to the concern owner who might be related or worked on similar file.

Suspect CL : https://chromium.googlesource.com/chromium/src/+/33fd0cb9308cad33938bc6cb7b69b1300af26e8b
             https://chromium.googlesource.com/chromium/src/+/84452f6f0c65b006ca8646553147f3386e8b57ca

ymalik@-- Could you please look into the issue, kindly re-assign if this is not related to your changes.


Thank You.

Comment 8 by e...@chromium.org, Sep 28 2017

Status: WontFix (was: Assigned)
Stack overflows for deeply nested content are considered WontFix.

The test case recursively nests an element using the dom mutation API. This is something like the 40th version of this bug filed in the last month or two.
Can we please stop filing bugs for stack-overflows generated by that test?

Project Member

Comment 9 by ClusterFuzz, Oct 1 2017

Labels: Test-Predator-AutoComponents
Automatically applying components based on information from OWNERS files. If this seems incorrect, please apply the Test-Predator-Wrong-Components label.
Project Member

Comment 10 by ClusterFuzz, Oct 5 2017

Labels: Needs-Feedback
ClusterFuzz testcase 5433233616666624 is still reproducing on tip-of-tree build (trunk).

If this testcase was not reproducible locally or unworkable, ignore this notification and we will file another bug soon with hopefully a better and workable testcase.

Otherwise, if this is not intended to be fixed (e.g. this is an intentional crash), please add ClusterFuzz-Ignore label to prevent future bug filing with similar crash stacktrace.
Labels: -Test-Predator-AutoComponents Test-Predator-Auto-Components

Sign in to add a comment