New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 827814 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Apr 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Stack-overflow in LayoutUnit

Project Member Reported by ClusterFuzz, Mar 31 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5145628058058752

Fuzzer: inferno_twister
Job Type: linux_lsan_chrome_mp
Platform Id: linux

Crash Type: Stack-overflow
Crash Address: 0x7ffd9fd59ef8
Crash State:
  LayoutUnit
  ComputedMarginValues
  blink::LayoutTable::UpdateLogicalWidth
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_lsan_chrome_mp&range=523898:523900

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5145628058058752

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Mar 31 2018

Components: Blink>Layout Platform
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Cc: brajkumar@chromium.org
Labels: -Pri-1 M-66 Test-Predator-Wrong CF-NeedsTriage Pri-2
Unable to find actual suspect through code search and also observing no related changes under regression range, hence adding appropriate label and requesting someone from blink team to look in to this issue.

Thanks!

Comment 3 by e...@chromium.org, Apr 4 2018

Status: WontFix (was: Untriaged)
Stack overflow for deeply nested DOM is considered WontFix.
Project Member

Comment 4 by ClusterFuzz, Apr 11 2018

Labels: Needs-Feedback
ClusterFuzz testcase 5145628058058752 is still reproducing on tip-of-tree build (trunk).

If this testcase was not reproducible locally or unworkable, ignore this notification and we will file another bug soon with hopefully a better and workable testcase.

Otherwise, if this is not intended to be fixed (e.g. this is an intentional crash), please add ClusterFuzz-Ignore label to prevent future bug filing with similar crash stacktrace.

Sign in to add a comment