Chrome Version: ToT @ r584130
OS: Linux
What steps will reproduce the problem?
(1) Load https://www.w3.org/TR/html52/single-page.html with LayoutNG enabled
(2) Wait until load
(3) Press Ctrl+A
Crashes with the following stack trace:
Received signal 11 SEGV_MAPERR 00000000007c
#0 0x55d9241cce7c base::debug::StackTrace::StackTrace()
#1 0x55d9241cc951 base::debug::(anonymous namespace)::StackDumpSignalHandler()
#2 0x7f715717e0c0 <unknown>
#3 0x55d927856266 blink::IsBeforeSoftLineBreak()
#4 0x55d927855ab4 blink::LayoutSelection::ComputeSelectionStatus()
#5 0x55d9281245a6 blink::PaintInvalidator::InvalidatePaint()
#6 0x55d92816c6cd blink::PrePaintTreeWalk::WalkInternal()
#7 0x55d92816b4e7 blink::PrePaintTreeWalk::Walk()
#8 0x55d92816b54b blink::PrePaintTreeWalk::Walk()
#9 0x55d92816b54b blink::PrePaintTreeWalk::Walk()
#10 0x55d92816b54b blink::PrePaintTreeWalk::Walk()
#11 0x55d92816b54b blink::PrePaintTreeWalk::Walk()
#12 0x55d92816b54b blink::PrePaintTreeWalk::Walk()
#13 0x55d92816b54b blink::PrePaintTreeWalk::Walk()
#14 0x55d92816b54b blink::PrePaintTreeWalk::Walk()
#15 0x55d92816b54b blink::PrePaintTreeWalk::Walk()
#16 0x55d92816af3c blink::PrePaintTreeWalk::Walk()
#17 0x55d92816a504 blink::PrePaintTreeWalk::WalkTree()
#18 0x55d9279eed6c blink::LocalFrameView::RunPrePaintLifecyclePhase()
#19 0x55d9279ee09e blink::LocalFrameView::UpdateLifecyclePhasesInternal()
#20 0x55d9279ecf5a blink::LocalFrameView::UpdateLifecyclePhases()
#21 0x55d9279ed3c1 blink::LocalFrameView::UpdateAllLifecyclePhasesExceptPaint()