New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 823593 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Mar 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 1
Type: Bug-Regression



Sign in to add a comment

Stack-overflow in blink::LayoutBox::ShouldBeConsideredAsReplaced

Project Member Reported by ClusterFuzz, Mar 20 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5684014732804096

Fuzzer: inferno_layout_test_unmodified
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: Stack-overflow
Crash Address: 0x7fff52dbef60
Crash State:
  blink::LayoutBox::ShouldBeConsideredAsReplaced
  blink::LayoutBlockFlow::AvoidsFloats
  blink::LayoutBox::ComputeMarginsForDirection
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=544006:544012

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5684014732804096

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Mar 20 2018

Components: Blink>Layout
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Cc: brajkumar@chromium.org
Labels: -Type-Bug M-67 Test-Predator-Wrong Type-Bug-Regression
Unable to find actual suspect through code search and also observing no CL under regression range, hence adding appropriate label and leaving it as untriaged for further updates.

Thanks!
Labels: CF-NeedsTriage

Comment 4 by e...@chromium.org, Mar 21 2018

Status: WontFix (was: Untriaged)
Project Member

Comment 5 by ClusterFuzz, Mar 22 2018

ClusterFuzz has detected this issue as fixed in range 544790:544829.

Detailed report: https://clusterfuzz.com/testcase?key=5684014732804096

Fuzzer: inferno_layout_test_unmodified
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: Stack-overflow
Crash Address: 0x7fff52dbef60
Crash State:
  blink::LayoutBox::ShouldBeConsideredAsReplaced
  blink::LayoutBlockFlow::AvoidsFloats
  blink::LayoutBox::ComputeMarginsForDirection
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=544006:544012
Fixed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=544790:544829

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5684014732804096

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Sign in to add a comment