Issue metadata
Sign in to add a comment
|
CHECK failure: storage_.is_populated_ in optional.h |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5046519288561664 Fuzzer: ifratric-browserfuzzer-v3 Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: storage_.is_populated_ in optional.h _ZNO4base8OptionalIN5blink7IntRectEEdeEv blink::ObjectPaintPropertyTreeBuilder::UpdateForSelf Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=550193:550200 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5046519288561664 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
May 1 2018
Crash in prepaint associated with clips and/or mask, it seems.
,
May 1 2018
,
May 2 2018
(Sorry, I put a wrong bug number in the CL.) The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/f9c2cf42a20b6b7ebbd1b4d005ffff9cbb623e64 commit f9c2cf42a20b6b7ebbd1b4d005ffff9cbb623e64 Author: Xianzhu Wang <wangxianzhu@chromium.org> Date: Wed May 02 04:52:42 2018 [PE] Fix missing InvalidateClipPathCache in a corner case InvalidateClipPathCache should be called whenever style.ClipPath() changes. Previously it missed a branch. Bug: 835828 Cq-Include-Trybots: master.tryserver.blink:linux_trusty_blink_rel;master.tryserver.chromium.linux:linux_layout_tests_slimming_paint_v2 Change-Id: Ifd178ac2b2b695239a7aa0b69cdbe4f41cad5af2 Reviewed-on: https://chromium-review.googlesource.com/1038425 Commit-Queue: Xianzhu Wang <wangxianzhu@chromium.org> Reviewed-by: Tien-Ren Chen <trchen@chromium.org> Cr-Commit-Position: refs/heads/master@{#555312} [modify] https://crrev.com/f9c2cf42a20b6b7ebbd1b4d005ffff9cbb623e64/third_party/WebKit/LayoutTests/FlagExpectations/enable-slimming-paint-v2 [add] https://crrev.com/f9c2cf42a20b6b7ebbd1b4d005ffff9cbb623e64/third_party/WebKit/LayoutTests/paint/clipath/change-mask-clip-path-multicol-crash.html [modify] https://crrev.com/f9c2cf42a20b6b7ebbd1b4d005ffff9cbb623e64/third_party/blink/renderer/core/layout/layout_object.cc
,
May 2 2018
,
May 2 2018
ClusterFuzz has detected this issue as fixed in range 555311:555312. Detailed report: https://clusterfuzz.com/testcase?key=5046519288561664 Fuzzer: ifratric-browserfuzzer-v3 Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: storage_.is_populated_ in optional.h _ZNO4base8OptionalIN5blink7IntRectEEdeEv blink::ObjectPaintPropertyTreeBuilder::UpdateForSelf Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=550193:550200 Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=555311:555312 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5046519288561664 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
May 2 2018
ClusterFuzz testcase 5046519288561664 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
May 2 2018
This is an SPv175 regression, and might also be the cause of bug 831634 .
,
May 2 2018
This bug requires manual review: M67 has already been promoted to the beta branch, so this requires manual review Please contact the milestone owner if you have questions. Owners: cmasso@(Android), cmasso@(iOS), kbleicher@(ChromeOS), govind@(Desktop) For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
May 2 2018
How safe is the change to merge to M67?
,
May 2 2018
Yes, it's safe.
,
May 2 2018
Just noticed CL listed at #4 didn't make it to canary yet. Pls update the bug with canary result tomorrow.
,
May 2 2018
Reopen for reminding me the merge.
,
May 3 2018
The NextAction date has arrived: 2018-05-03
,
May 3 2018
The bug is about a DCHECK failure, so it's not directly testable in a canary build. Verified on ToT with DCHECK on, and by clusterfuzz bot. There could be a test case showing rendering failure in an official build, but not available for now.
,
May 3 2018
This bug requires manual review: M67 has already been promoted to the beta branch, so this requires manual review Please contact the milestone owner if you have questions. Owners: cmasso@(Android), cmasso@(iOS), kbleicher@(ChromeOS), govind@(Desktop) For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
May 3 2018
Approving merge to M67 branch 3396 based on comments #11 and #16. Please merge ASAP. Thank you.
,
May 3 2018
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/1326f4b11bf2925ac1fb944961bd9a8af10141af commit 1326f4b11bf2925ac1fb944961bd9a8af10141af Author: Xianzhu Wang <wangxianzhu@chromium.org> Date: Thu May 03 17:02:04 2018 [PE] Fix missing InvalidateClipPathCache in a corner case InvalidateClipPathCache should be called whenever style.ClipPath() changes. Previously it missed a branch. TBR=wangxianzhu@chromium.org (cherry picked from commit f9c2cf42a20b6b7ebbd1b4d005ffff9cbb623e64) Bug: 838528 Cq-Include-Trybots: master.tryserver.blink:linux_trusty_blink_rel;master.tryserver.chromium.linux:linux_layout_tests_slimming_paint_v2 Change-Id: Ifd178ac2b2b695239a7aa0b69cdbe4f41cad5af2 Reviewed-on: https://chromium-review.googlesource.com/1038425 Commit-Queue: Xianzhu Wang <wangxianzhu@chromium.org> Reviewed-by: Tien-Ren Chen <trchen@chromium.org> Cr-Original-Commit-Position: refs/heads/master@{#555312} Reviewed-on: https://chromium-review.googlesource.com/1042745 Reviewed-by: Xianzhu Wang <wangxianzhu@chromium.org> Cr-Commit-Position: refs/branch-heads/3396@{#455} Cr-Branched-From: 9ef2aa869bc7bc0c089e255d698cca6e47d6b038-refs/heads/master@{#550428} [modify] https://crrev.com/1326f4b11bf2925ac1fb944961bd9a8af10141af/third_party/WebKit/LayoutTests/FlagExpectations/enable-slimming-paint-v2 [add] https://crrev.com/1326f4b11bf2925ac1fb944961bd9a8af10141af/third_party/WebKit/LayoutTests/paint/clipath/change-mask-clip-path-multicol-crash.html [modify] https://crrev.com/1326f4b11bf2925ac1fb944961bd9a8af10141af/third_party/blink/renderer/core/layout/layout_object.cc
,
May 3 2018
|
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by ClusterFuzz
, May 1 2018Labels: Test-Predator-Auto-Components