New issue
Advanced search Search tips

Issue 855829 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 855026
Owner:
Closed: Jun 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

CHECK failure: layout_object->CanBeSelectionLeaf() in layout_selection.cc

Project Member Reported by ClusterFuzz, Jun 23 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=4847729273208832

Fuzzer: marty_html_twiddler
Job Type: linux_debug_chrome
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  layout_object->CanBeSelectionLeaf() in layout_selection.cc
  blink::CalcSelectionRangeAndSetSelectionState
  blink::LayoutSelection::Commit
  
Sanitizer: address (ASAN)

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4847729273208832

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Cc: pnangunoori@chromium.org
Components: Blink>Paint
Labels: M-68 Test-Predator-Wrong
Owner: yoichio@chromium.org
Status: Assigned (was: Untriaged)
Predator and CL could not provide any possible suspects.
Using the code search for the file, “layout_selection.cc” assigning to concern owner from GIT blame.
Suspecting Commit#
https://chromium.googlesource.com/chromium/src/+/98d5a361a2475c78c7c746e9cc3284fb548bab5a
https://chromium.googlesource.com/chromium/src/+/022cebe871e53ec3bc6950f747b27a349a0aaf56
https://chromium.googlesource.com/chromium/src/+/7f5c4e125569b2763c9cc96b39e6ec9be9b4d3a3

@yoichio -- Could you please look into this issue, kindly reassign if it has nothing to do with your changes.
Thank You.

Mergedinto: 855026
Status: Duplicate (was: Assigned)
Project Member

Comment 3 by ClusterFuzz, Jul 7

ClusterFuzz has detected this issue as fixed in range 572928:572930.

Detailed report: https://clusterfuzz.com/testcase?key=4847729273208832

Fuzzer: marty_html_twiddler
Job Type: linux_debug_chrome
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  layout_object->CanBeSelectionLeaf() in layout_selection.cc
  blink::CalcSelectionRangeAndSetSelectionState
  blink::LayoutSelection::Commit
  
Sanitizer: address (ASAN)

Fixed: https://clusterfuzz.com/revisions?job=linux_debug_chrome&range=572928:572930

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4847729273208832

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Sign in to add a comment