New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 798811 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Feb 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

CHECK failure: !layout_and_paint_async_callback_ in render_widget_compositor.cc

Project Member Reported by ClusterFuzz, Jan 3 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=4678804059717632

Fuzzer: mbarbella_js_mutation_layout
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  !layout_and_paint_async_callback_ in render_widget_compositor.cc
  content::RenderWidgetCompositor::LayoutAndPaintAsync
  blink::WebViewImpl::LayoutAndPaintAsync
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_debug_content_shell_drt&range=420229:420262

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4678804059717632

Additional requirements: Requires Gestures

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Jan 3 2018

Components: Blink Internals>Compositing
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Project Member

Comment 2 by ClusterFuzz, Jan 3 2018

Cc: hush@chromium.org ben@chromium.org ericwilligers@chromium.org
Labels: Test-Predator-Auto-CC
Automatically adding ccs based on suspected regression changelists:

Enforce capability spec renderer <--> browser. by ben@chromium.org - https://chromium.googlesource.com/chromium/src/+/c70c0e365340a5426fa1f68f0f8c7008cb94bf5e

Fix the scale of Drag and Drop shadow image. by hush@chromium.org - https://chromium.googlesource.com/chromium/src/+/adba2165f4c6e1c7d4a78179d6e066aa8e37f938

CSS Motion Path: offset-anchor and offset-position by ericwilligers@chromium.org - https://chromium.googlesource.com/chromium/src/+/72e3e282b889aa86071423648033f81d8bfc7b2d

If this is incorrect, please apply the Test-Predator-Wrong-CLs label.
Components: -Blink
Cc: kkaluri@chromium.org
Labels: M-64
Owner: hajimehoshi@chromium.org
Status: Assigned (was: Untriaged)
Using Code Search for the file, "render_widget_compositor.cc" assigning to the concern owner who might be related.

Suspect CL : https://chromium.googlesource.com/chromium/src/+/a7e564426b4bff15e69a5cec84a1e4f1af03ad02

hajimehoshi@ -- Could you please look into the issue, kindly re-assign if this is not related to your changes.
Thank You.
Hmm, I couldn't reproduce this on my local machine (ASAN build). Is this still the case?
Project Member

Comment 6 by ClusterFuzz, Feb 17 2018

ClusterFuzz has detected this issue as fixed in range 537415:537416.

Detailed report: https://clusterfuzz.com/testcase?key=4678804059717632

Fuzzer: mbarbella_js_mutation_layout
Job Type: linux_debug_content_shell_drt
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  !layout_and_paint_async_callback_ in render_widget_compositor.cc
  content::RenderWidgetCompositor::LayoutAndPaintAsync
  blink::WebViewImpl::LayoutAndPaintAsync
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_debug_content_shell_drt&range=420229:420262
Fixed: https://clusterfuzz.com/revisions?job=linux_debug_content_shell_drt&range=537415:537416

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4678804059717632

Additional requirements: Requires Gestures

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 7 by ClusterFuzz, Feb 17 2018

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 4678804059717632 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment