New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 617556 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Last visit > 30 days ago
Closed: Mar 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug

Blocked on:
issue 703537



Sign in to add a comment

Undefined-shift in big2_prologTok

Project Member Reported by ClusterFuzz, Jun 6 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6133756083830784

Fuzzer: libfuzzer_expat_xml_parse_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  big2_prologTok
  prologProcessor
  prologInitProcessor
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=397275:397295

Minimized Testcase (0.00 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv96WmHXP5CR3swMy4MNK0i6V-M8YgMrESzP53d05sS89i5BciBN_rDtYlQgtkjJAmbNy2c33UAqc7gw1wqtQLuWuubyuurUQjSXBaxUpDLWVud_OR0DK5J537a2qE7PWmyofxOnllM2KSeldlAT-zCljmuie8w
<?


Filer: mmoroz

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Cc: mmoroz@chromium.org kcc@chromium.org dominicc@chromium.org aizatsky@chromium.org
Components: Blink>XML
Labels: -Pri-1 Pri-2
Bad thing #1: we don't have an owner for third_party/expat.
Bad thing #2: we have both libxml and expat in Chromium :(
Project Member

Comment 2 by ClusterFuzz, Jun 27 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6133756083830784

Fuzzer: libfuzzer_expat_xml_parse_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  big2_prologTok
  prologProcessor
  prologInitProcessor
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=397275:397295

Minimized Testcase (0.00 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv97R2JKdc5ALQEhAO8rKQjqTuomHpzl4a_B8glOAVDGYf70_kjiFenVJgZTLEuT2rTShkLT5N50N84IOuAyGIQlr-vuF8sd6VSz6m2fKIhhoxrFWbTE-123zmW9SDrT43XTCXtogW2KJNfxImWGlDRk6QsM8UA?testcase_id=6133756083830784
<?


See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 3 by ClusterFuzz, Jun 29 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6498488057856000

Fuzzer: libfuzzer_expat_xml_parse_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  big2_prologTok
  prologProcessor
  prologInitProcessor
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=397275:397295

Minimized Testcase (0.00 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv95rslvRhGwIFxFjF2y1zJKaVQ-HqNlGHacZ-_4L7TbHbCGqI0Pg8ustDOR9o-iu19nSaiRr3gwD6H3oooDHDV1LBo9XHudhk_iFG5lyx4f9MK9ptso_KKJAxGwd6YvBZfY1cIywyVfUf32I-s3gimSKMH_Ffg?testcase_id=6498488057856000
<?


Filer: mmoroz

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
Project Member

Comment 4 by ClusterFuzz, Jul 6 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6498488057856000

Fuzzer: libfuzzer_expat_xml_parse_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  big2_prologTok
  prologProcessor
  prologInitProcessor
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=397275:397295

Minimized Testcase (0.00 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv95rslvRhGwIFxFjF2y1zJKaVQ-HqNlGHacZ-_4L7TbHbCGqI0Pg8ustDOR9o-iu19nSaiRr3gwD6H3oooDHDV1LBo9XHudhk_iFG5lyx4f9MK9ptso_KKJAxGwd6YvBZfY1cIywyVfUf32I-s3gimSKMH_Ffg?testcase_id=6498488057856000
<?


See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by ClusterFuzz, Jul 13 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6240867916709888

Fuzzer: libfuzzer_expat_xml_parse_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  big2_prologTok
  prologProcessor
  prologInitProcessor
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=397275:397295

Minimized Testcase (0.00 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv976RlFZg99SS2fqIJV8NsSTCVLBqzLG4PbsDvHFHgWUv_9cTD8MI5nLX6M9aH7ai6gf4keIqc8pwUa_DOMlk9WYcRdyVHtFXLmnfX-aahEh4lpHG28MrZyaq6DsOw8irfMGPDUWc_ZOODP92e-yhLLos4rmDg?testcase_id=6240867916709888
<?


Filer: ajha

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

Comment 6 by mmoroz@chromium.org, Jul 15 2016

Owner: tommi@chromium.org
The same as per  bug 628195 .

Comment 7 by tommi@chromium.org, Jul 15 2016

Cc: tommi@chromium.org
Owner: pthatcher@chromium.org
Project Member

Comment 8 by ClusterFuzz, Jul 29 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6679707215200256

Fuzzer: libfuzzer_expat_xml_parse_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  big2_prologTok
  prologProcessor
  prologInitProcessor
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=397275:397295

Minimized Testcase (0.00 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv9632E2_16Qf-fiYKPfhadOmcjblGtxzOpddyvY4XnSRSYGdnlaYGxdHb_ob_LYF6RVP3Qxm7KpaTpJ0EwxUsucbNfBV5a-wZRokLZfYOv_qOPG8qLMECczJgE2wc2UmbKIlQabngXFR4HUnj3sk2XDi5WR1Jg?testcase_id=6679707215200256
<?


Filer: rnimmagadda

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
Gentle Ping.

@pthatcher: Could you please provide some update on this issue.

Thank you.
Project Member

Comment 10 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 11 by ClusterFuzz, Mar 24 2017

ClusterFuzz has detected this issue as fixed in range 459024:459032.

Detailed report: https://clusterfuzz.com/testcase?key=6679707215200256

Fuzzer: libfuzzer_expat_xml_parse_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  big2_prologTok
  prologInitProcessor
  XML_ParseBuffer
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=397275:397295
Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=459024:459032

Reproducer Testcase: https://clusterfuzz.com/download/AMIfv95dnCQJn3WZjflG-zfAhp9id0x1-KnCsAvdbh1gyMtPG6uGLxYMQQwuQnAvuWmjxtOIPkTBd5shylKeAq-DipUR040z1Hq80K79EtkMAiNqZL38C5F_w0PDBDAQTtCfAAM6icv_1xX8XMLvd2qsxvjs35xWGF_ap5DIMbNvs1fB2kBspRaTStfFIgxxOMRFPiUKUfTNyGg1SMjrh6rdIa5s5NwN5qeOW3EiO5d6XCANtyfmTjvD62tpk2Xw8klFvLgAArQHKK_86CHQFuPii0dKqqi-HkSi7oq4yy_Dsrj-59dbV4fjzIEH0hpksHO-habrIATIBF7jsY3HiqMum6q0YpuxkAKrdhR21cCwGaPTSXKrtUw?testcase_id=6679707215200256


See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 12 by ClusterFuzz, Mar 24 2017

ClusterFuzz has detected this issue as fixed in range 459024:459032.

Detailed report: https://clusterfuzz.com/testcase?key=6240867916709888

Fuzzer: libfuzzer_expat_xml_parse_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  big2_prologTok
  prologInitProcessor
  XML_ParseBuffer
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=397275:397295
Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=459024:459032

Reproducer Testcase: https://clusterfuzz.com/download/AMIfv94QB5Oyi-W9dAQnwqoxjMW1C2sZcOcgWyM4AsSTi3YPrBnAzHn3WUoUoPBAO3dK4UYEgnUXxGaJwOg20z-taZHWzOfoMaZTb2mbd6TEsiXN8mK7knlUxZg68359YUqIM2vny7AqCLPk6pXlqVKSdoXEQtIJvrd52LaY6hzOyURppeo-1Qi7Iva1UQveSRicejjnkKrIc--O8yzXGMqVQy23xmUvYyxkbRP34-lzFAIif4fMXQ7eEc75BnDVFuA0u64G2U6J4f6jFmAaSKASaUQ_qnMo6ZlyIVoSYOYCReJB6HF0KudngnmAW8yhGgpkyCIA7MsPgXaZLZ5T9GASNZLmUuIrC4NLBoG7hOPO6iR4cK-o5Bw?testcase_id=6240867916709888


See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 13 by ClusterFuzz, Mar 24 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Available)
ClusterFuzz testcase 6240867916709888 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Blockedon: 703537
qingchengl fixed this with the expat roll in r459025.

Sign in to add a comment