New issue
Advanced search Search tips

Issue 775709 link

Starred by 1 user

Issue metadata

Status: Duplicate
Owner:
Closed: Oct 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Mac
Pri: 2
Type: Bug



Sign in to add a comment

CHECK failure: list_node in ListItemOrdinal.cpp

Project Member Reported by ClusterFuzz, Oct 17 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5649836379734016

Fuzzer: ifratric-browserfuzzer-v3
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  list_node in ListItemOrdinal.cpp
  blink::ListItemOrdinal::ItemInsertedOrRemoved
  blink::LayoutObjectChildList::RemoveChildNode
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=467234:467250

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5649836379734016

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Oct 18 2017

Labels: OS-Android OS-Mac
Cc: kkaluri@chromium.org
Components: Blink>Layout
Labels: M-62 Test-Predator-Wrong
Owner: kojii@chromium.org
Status: Assigned (was: Untriaged)
Predator could not provide any possible suspects.

Using the CL for the file, “ListItemOrdinal.cpp” assigning to concern owner for his recent work on this file.

Suspect CL : https://chromium.googlesource.com/chromium/src/+/6541835c4e9db26be7685581b1f263cf9a3f17c0

kojii@ -- Could you please look into this issue, kindly reassign if it has nothing to do with your changes.


Thank You.

Comment 3 by e...@chromium.org, Oct 18 2017

Labels: -Pri-1 Pri-2

Comment 4 by kojii@chromium.org, Oct 20 2017

Mergedinto: 767403
Status: Duplicate (was: Assigned)
Project Member

Comment 5 by ClusterFuzz, Oct 21 2017

ClusterFuzz has detected this issue as fixed in range 510436:510509.

Detailed report: https://clusterfuzz.com/testcase?key=5649836379734016

Fuzzer: ifratric-browserfuzzer-v3
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  list_node in ListItemOrdinal.cpp
  blink::ListItemOrdinal::ItemInsertedOrRemoved
  blink::LayoutObjectChildList::RemoveChildNode
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=467234:467250
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=510436:510509

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5649836379734016

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Sign in to add a comment