New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 818405 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Abrt in blink::Document::UpdateStyleAndLayout

Project Member Reported by ClusterFuzz, Mar 3 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5361244417294336

Fuzzer: attekett_dom_fuzzer
Job Type: linux_tsan_chrome_mp
Platform Id: linux

Crash Type: Abrt
Crash Address: 0x05390000375e
Crash State:
  blink::Document::UpdateStyleAndLayout
  blink::Document::EnsurePaintLocationDataValidForNode
  blink::HTMLElement::offsetWidthForBinding
  
Sanitizer: thread (TSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_tsan_chrome_mp&range=523888:523922

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5361244417294336

Additional requirements: Requires Gestures

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Mar 3 2018

Components: Blink>DOM Blink>HTML
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Project Member

Comment 2 by ClusterFuzz, Mar 3 2018

Cc: zakerinasab@chromium.org loonyb...@chromium.org
Labels: Test-Predator-Auto-CC
Automatically adding ccs based on suspected regression changelists:

Add ImageData constructor from StaticBitmapImage by zakerinasab@chromium.org - https://chromium.googlesource.com/chromium/src/+/2c863229da24ed1cb180759c9342e7a5125fd6f5

Drop UseCounter usage measurement on view-source pages. by loonybear@chromium.org - https://chromium.googlesource.com/chromium/src/+/3f921557c4cb83453bfce0fe8637e489a90064ad

If this is incorrect, please let us know why and apply the Test-Predator-Wrong-CLs label.

Comment 3 by tkent@chromium.org, Mar 5 2018

Components: -Blink>HTML -Blink>DOM Blink>Layout
Cc: -zakerinasab@chromium.org
My CL only adds a new API. It doesn't change any existing behavior or call site.

Comment 5 by e...@chromium.org, Mar 6 2018

Components: -Blink>Layout Blink>Editing
Labels: -Pri-1 Pri-3

Comment 6 by e...@chromium.org, Mar 6 2018

Components: -Blink>Editing Blink>Layout
Labels: -Pri-3 Pri-1
Status: WontFix (was: Untriaged)
Unable to reproduce either with clusterfuzz tool or manually. No relevant changes in regression range.

Can we please stop filing bugs for tests marked "Requires Gestures"? It seems to be code for "unreproducible and without regression range".

Project Member

Comment 7 by ClusterFuzz, Mar 13 2018

Labels: Needs-Feedback
ClusterFuzz testcase 5361244417294336 is still reproducing on tip-of-tree build (trunk).

If this testcase was not reproducible locally or unworkable, ignore this notification and we will file another bug soon with hopefully a better and workable testcase.

Otherwise, if this is not intended to be fixed (e.g. this is an intentional crash), please add ClusterFuzz-Ignore label to prevent future bug filing with similar crash stacktrace.

Sign in to add a comment