New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 849339 link

Starred by 1 user

Issue metadata

Status: Verified
Owner: ----
Closed: Jun 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

CHECK failure: flow_thread_offset.MightBeSaturated() || PageLogicalTopForOffset(flow_thread_off

Project Member Reported by ClusterFuzz, Jun 4 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5200760636440576

Fuzzer: ifratric-browserfuzzer-v3
Job Type: linux_debug_chrome
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  flow_thread_offset.MightBeSaturated() || PageLogicalTopForOffset(flow_thread_off
  blink::LayoutMultiColumnSet::NextLogicalTopForUnbreakableContent
  blink::LayoutFlowThread::NextLogicalTopForUnbreakableContent
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_debug_chrome&range=552767:552775

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5200760636440576

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Jun 4 2018

Components: Blink>Layout
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Cc: brajkumar@chromium.org
Labels: M-69 Test-Predator-Wrong CF-NeedsTriage
Unable to find actual suspect through code search and also observing no suspected CL's under regression range, hence adding appropriate label and requesting someone from blink team to look in to this issue.

Thanks!

Comment 3 by e...@chromium.org, Jun 7 2018

Labels: -Pri-1 Pri-2
Status: Available (was: Untriaged)

Comment 4 by e...@chromium.org, Jun 7 2018

Components: -Blink>Layout Blink>Layout>MultiCol
Project Member

Comment 5 by ClusterFuzz, Jun 24 2018

ClusterFuzz has detected this issue as fixed in range 569793:569802.

Detailed report: https://clusterfuzz.com/testcase?key=5200760636440576

Fuzzer: ifratric-browserfuzzer-v3
Job Type: linux_debug_chrome
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  flow_thread_offset.MightBeSaturated() || PageLogicalTopForOffset(flow_thread_off
  blink::LayoutMultiColumnSet::NextLogicalTopForUnbreakableContent
  blink::LayoutFlowThread::NextLogicalTopForUnbreakableContent
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_debug_chrome&range=552767:552775
Fixed: https://clusterfuzz.com/revisions?job=linux_debug_chrome&range=569793:569802

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5200760636440576

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 6 by ClusterFuzz, Jun 24 2018

Labels: ClusterFuzz-Verified
Status: Verified (was: Available)
ClusterFuzz testcase 5200760636440576 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment