New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 617878 link

Starred by 0 users

Issue metadata

Status: Verified
Owner:
Closed: Aug 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Undefined-shift in uprv_decNumberFromString_56

Project Member Reported by ClusterFuzz, Jun 7 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6347964465545216

Fuzzer: libfuzzer_icu_number_format_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  uprv_decNumberFromString_56
  icu_56::DigitList::set
  icu_56::DecimalFormat::subparse
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=397764:398208

Minimized Testcase (0.02 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97NhKh6xzf-oDrWOHjfqURghkdfcJkndklVYYjuDpY-ERgmatrubCvtKPLJPGnv4KokzJ4T-LaFxLl6cOMyleBJabcVbct4yyu6OfqFpqW3w-SajxJlezp0t1AB_NIaYSvVLAREgp197VTi2JoWvHYZzSkNow

Filer: mmoroz

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Cc: mmoroz@chromium.org kcc@chromium.org aizatsky@chromium.org
Labels: -Pri-1 Pri-2
Owner: js...@chromium.org
Project Member

Comment 2 by ClusterFuzz, Jun 27 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6347964465545216

Fuzzer: libfuzzer_icu_number_format_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  uprv_decNumberFromString_56
  icu_56::DigitList::set
  icu_56::DecimalFormat::subparse
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=397764:398208

Minimized Testcase (0.02 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97Vo4r_r3a_tbCBfaE5LM9FWMmQCBUcEqlJ7XmEownAeNZU_u9XqYhsgoK7rbc5gkk1ZxJUW_AaVC_h82mYPzFMqvQKwvCz4uqYc5e4jtSWmUeud2fYAuBfkIwNyNtuvM-VdVjO7Op8Icwhh7-SxRhMlOxkRg?testcase_id=6347964465545216

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 3 by ClusterFuzz, Jun 29 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6153643388829696

Fuzzer: libfuzzer_icu_number_format_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  uprv_decNumberFromString_56
  icu_56::DigitList::set
  icu_56::DecimalFormat::subparse
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=397764:398208

Minimized Testcase (0.01 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv97B3u6OLzFMq55s5sRSxe91xdDS5giQuTXzLnKKjCUgAdveYcBdsh0lkyzn9ezshQv71Qi4ZnY1-RiZ_O47SYhwkfFhKGC6S2N_VYTIz_0A_GbmJa8WWzhodTW82yi4M9ACsEBbxtOTYPdw_GKbgVIuc362Cw?testcase_id=6153643388829696
0e003421061613:


Filer: mmoroz

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
Project Member

Comment 4 by ClusterFuzz, Jul 29 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5424889435783168

Fuzzer: libfuzzer_icu_number_format_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  uprv_decNumberFromString_56
  icu_56::DigitList::set
  icu_56::DecimalFormat::subparse
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=397764:398208

Minimized Testcase (0.01 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv95h9IcB044Gv1ffUh7ZKCpL5EhQfz_2Kx1DsYCpxt1On5Qndk7Kc_w1douxolgfiItS3x2dT9G7LMmRJdKJQz6kLkbikjqPwMzKndyHguig-cSyvNv4w58zUc94vtiblVBZgvGQGLFoQyrWtRNS7pFQwrKlRg?testcase_id=5424889435783168
40E7100000080


Filer: rnimmagadda

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
Gentle Ping.

@jshin: Could you please provide some update on this issue.

Thank you.
Project Member

Comment 6 by ClusterFuzz, Aug 26 2016

ClusterFuzz has detected this issue as fixed in range 413961:414068.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5424889435783168

Fuzzer: libfuzzer_icu_number_format_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  uprv_decNumberFromString_56
  icu_56::DigitList::set
  icu_56::DecimalFormat::subparse
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=397764:398208
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=413961:414068

Minimized Testcase (0.01 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv95h9IcB044Gv1ffUh7ZKCpL5EhQfz_2Kx1DsYCpxt1On5Qndk7Kc_w1douxolgfiItS3x2dT9G7LMmRJdKJQz6kLkbikjqPwMzKndyHguig-cSyvNv4w58zUc94vtiblVBZgvGQGLFoQyrWtRNS7pFQwrKlRg?testcase_id=5424889435783168
40E7100000080


See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 7 by ClusterFuzz, Aug 26 2016

ClusterFuzz has detected this issue as fixed in range 414399:414444.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6153643388829696

Fuzzer: libfuzzer_icu_number_format_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  uprv_decNumberFromString_56
  icu_56::DigitList::set
  icu_56::DecimalFormat::subparse
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=397764:398208
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=414399:414444

Minimized Testcase (0.01 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv97B3u6OLzFMq55s5sRSxe91xdDS5giQuTXzLnKKjCUgAdveYcBdsh0lkyzn9ezshQv71Qi4ZnY1-RiZ_O47SYhwkfFhKGC6S2N_VYTIz_0A_GbmJa8WWzhodTW82yi4M9ACsEBbxtOTYPdw_GKbgVIuc362Cw?testcase_id=6153643388829696
0e003421061613:


See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 8 by ClusterFuzz, Aug 26 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Available)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 9 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment