New issue
Advanced search Search tips

Issue 616251 link

Starred by 0 users

Issue metadata

Status: WontFix
Owner:
Closed: Dec 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug-Regression



Sign in to add a comment

Integer-overflow in views::DesktopWindowTreeHostX11::SetOpacity

Project Member Reported by ClusterFuzz, May 31 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5647958381166592

Fuzzer: tokenfuzz_pdf_march16
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  views::DesktopWindowTreeHostX11::SetOpacity
  views::DesktopDragDropClientAuraX11::CreateDragWidget
  views::DesktopDragDropClientAuraX11::StartDragAndDrop
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=370022:370027

Minimized Testcase (3.32 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96Jks4bwAdmrGVxY5588Tz3_pBJe0g_4cPcqVBZsGKHVgUgSfqqpvX2iY4p46aiPTIuECmINkalqgD6Da03qw_RYEJOlbqe5j_pA8t_CPOCqmaXvLW2txXcTLRqx3jSOQq23d5b5QInfBi9DD3MnZEFpruWRg

Additional requirements: Requires Gestures

Filer: ivancic

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Project Member

Comment 1 by ClusterFuzz, May 31 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5647958381166592

Fuzzer: tokenfuzz_pdf_march16
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  views::DesktopWindowTreeHostX11::SetOpacity
  views::DesktopDragDropClientAuraX11::CreateDragWidget
  views::DesktopDragDropClientAuraX11::StartDragAndDrop
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=370022:370027

Minimized Testcase (3.32 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96Jks4bwAdmrGVxY5588Tz3_pBJe0g_4cPcqVBZsGKHVgUgSfqqpvX2iY4p46aiPTIuECmINkalqgD6Da03qw_RYEJOlbqe5j_pA8t_CPOCqmaXvLW2txXcTLRqx3jSOQq23d5b5QInfBi9DD3MnZEFpruWRg

Additional requirements: Requires Gestures

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Components: Internals>Views
Labels: -Type-Bug M-51 Type-Bug-Regression
Owner: sky@chromium.org
Status: Assigned (was: Available)
No CL in the regression range changes the crashed files. The result is the blame information.

Author: sky
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/8b858455d0b6ef5155103a0c91956ee259813391
Time: Wed May 25 20:35:49 2016
The CL last changed line 857 of file desktop_window_tree_host_x11.cc, which is stack frame 0.

Author: pkotwicz@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/a67636db9e1175c83cb861d3fdcfdcb1783935af
Time: Tue Aug 12 18:16:27 2014
The CL last changed line 1200 of file desktop_drag_drop_client_aurax11.cc, which is stack frame 1.

Author: pkotwicz@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/a67636db9e1175c83cb861d3fdcfdcb1783935af
Time: Tue Aug 12 18:16:27 2014
The CL last changed line 696 of file desktop_drag_drop_client_aurax11.cc, which is stack frame 2.

Author: xhwang@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/dd32b127ce5deac52b24f493dac79195a30bf138
Time: Sat May 04 14:17:11 2013
The CL last changed line 855 of file web_contents_view_aura.cc, which is stack frame 3.

Author: pkotwicz@chromium.org
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/deb6bb71c8aa5c696d239ceb677331b41c47cab5
Time: Mon Jul 09 20:16:59 2012
The CL last changed line 1085 of file render_view_host_impl.cc, which is stack frame 4.

Author: mdempsky
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/6e7f615f49056439312aad3fcdd2284e2bd69647
Time: Wed Dec 10 03:10:59 2014
The CL last changed line 173 of file tuple.h, which is stack frame 5.

Author: mdempsky
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/8a5190449d48e06efa581390426dfa3bb6750f4c
Time: Tue Feb 09 05:41:47 2016
The CL last changed line 26 of file ipc_message_templates.h, which is stack frame 6.

Suspected Project: chromium
====================================

Above is the only CL from findit and the changes made to file "desktop_window_tree_host_x11.cc" from the frame #0 is more related to it. 

sky@ :Could you please look into this issue if it is related to your change, else please route this issue to an appropriate dev person.

Thanks,
Components: Tools>Test>FindIt>CorrectResult
Labels: findit-for-crash Te-Logged
Project Member

Comment 4 by ClusterFuzz, Jul 16 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5302388554727424

Fuzzer: svg_more_tokenfuzz
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  views::DesktopWindowTreeHostX11::SetOpacity
  views::DesktopDragDropClientAuraX11::CreateDragWidget
  views::DesktopDragDropClientAuraX11::StartDragAndDrop
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=370022:370027

Minimized Testcase (0.20 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv94os3EqFQFRRsZGBRLMdVXvwD2Y7O1BgSN73UTOhkoWDYsZiPdahQcWUeW3L7CL2XvAq9fm6YPfgWw3CfQsx2Za_PdHGyGcYR-cv2hBnPCNPaWDCeBlVSQe0Id-NKKedeEMdKcCmIkv6Lz1dVHZkmv63DZE8Q?testcase_id=5302388554727424
                                            </a>
                                        <li class="ru">
                                            <a href="http://www.homeaway.ru/" alt="������������">


Additional requirements: Requires Gestures

Filer: thestig

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Cc: pkotw...@chromium.org
Labels: -M-51
Labels: Pri-2
Project Member

Comment 7 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 8 by ClusterFuzz, Dec 22 2016

Status: WontFix (was: Assigned)
ClusterFuzz testcase 5302388554727424 is flaky and no longer reproduces, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment