Crash in SkImage::isTextureBacked |
|||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4760558117322752 Fuzzer: mbarbella_js_mutation_layout Job Type: linux_asan_content_shell_drt Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: SkImage::isTextureBacked blink::ImageBitmapRenderingContext::transferFromImageBitmap blink::ImageBitmapRenderingContextV8Internal::transferFromImageBitmapMethodCallb Minimized Testcase (11.47 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95iomAtwLrZMOk9KDb9pePmOPan8wVkaZI5bZnoIKmO33nUzQllkFJfqqLJtRXumXteOeCy4X8oh2KZJH9DCS0TB5a5lLclXSzCbSaDd59acTtPhpo9BcoOiUeu4XyAen2hlIC1Q6dmNL0HU76NDICdSjP-nA?testcase_id=4760558117322752 Filer: mummareddy See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jun 24 2016
Justin, I suspect skImage in ImageBitmapRenderingContext::transferFromImageBitmap is null. Do you think this is possible?
,
Jun 24 2016
Moving this nonessential bug to the next milestone. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jul 3 2016
This issue is Pri-1 but has already been moved once. Lowering the priority and moving to the next milestone. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jul 6 2016
ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4760558117322752 Fuzzer: mbarbella_js_mutation_layout Job Type: linux_asan_content_shell_drt Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: SkImage::isTextureBacked blink::ImageBitmapRenderingContext::transferFromImageBitmap blink::ImageBitmapRenderingContextV8Internal::transferFromImageBitmapMethodCallb Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_content_shell_drt&range=395055:395067 Minimized Testcase (11.47 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95iomAtwLrZMOk9KDb9pePmOPan8wVkaZI5bZnoIKmO33nUzQllkFJfqqLJtRXumXteOeCy4X8oh2KZJH9DCS0TB5a5lLclXSzCbSaDd59acTtPhpo9BcoOiUeu4XyAen2hlIC1Q6dmNL0HU76NDICdSjP-nA?testcase_id=4760558117322752 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jul 6 2016
ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4760558117322752 Fuzzer: mbarbella_js_mutation_layout Job Type: linux_asan_content_shell_drt Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: SkImage::isTextureBacked blink::ImageBitmapRenderingContext::transferFromImageBitmap blink::ImageBitmapRenderingContextV8Internal::transferFromImageBitmapMethodCallb Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_content_shell_drt&range=395055:395067 Minimized Testcase (11.47 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95iomAtwLrZMOk9KDb9pePmOPan8wVkaZI5bZnoIKmO33nUzQllkFJfqqLJtRXumXteOeCy4X8oh2KZJH9DCS0TB5a5lLclXSzCbSaDd59acTtPhpo9BcoOiUeu4XyAen2hlIC1Q6dmNL0HU76NDICdSjP-nA?testcase_id=4760558117322752 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jul 6 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||
►
Sign in to add a comment |
|||||
Comment 1 by mummare...@chromium.org
, Jun 23 2016Labels: findit-wrong Te-Logged M-52
Owner: bsalomon@chromium.org
Status: Assigned (was: Available)