New issue
Advanced search Search tips

Issue 623712 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Jul 2016
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in base::LinearHistogram::FactoryGet

Project Member Reported by ClusterFuzz, Jun 27 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4544429121863680

Fuzzer: sugoi_filter_fuzzer
Job Type: linux_asan_filter_fuzz_stub
Platform Id: linux

Crash Type: UNKNOWN WRITE
Crash Address: 0x000000000000
Crash State:
  base::LinearHistogram::FactoryGet
  skia::HistogramEnumeration
  SkBaseDevice::LogDrawScaleFactor
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_filter_fuzz_stub&range=376765:376801

Minimized Testcase (0.09 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97YtPYWaUgnoW1y7J-6J0TZHrh95TahstZNmwB8nzDHSUIXFpAY_ufQjsCP0sy9TZMPUVoMZ-xFJL_RWTO3a5dLA-Ef9erzBIEPD_y1UrXnxTG0YgJcxVjvgvbOrDBvB5Y-TGLeyYHr99f0ZM7gjRDK78y2sg?testcase_id=4544429121863680

Filer: mmohammad

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Owner: ericrk@chromium.org
Status: Assigned (was: Available)
Suspected CL could be
https://chromium.googlesource.com/chromium/src/+/4e7c2b3384ce41324ec60f84cd36d063b6db6d76%5E%21/skia/ext/skia_histogram.cc

Last updated by  ericrk@ weeks ago , please have a look and reassign if needed.

Thank you.
Project Member

Comment 2 by ClusterFuzz, Jul 6 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4544429121863680

Fuzzer: sugoi_filter_fuzzer
Job Type: linux_asan_filter_fuzz_stub
Platform Id: linux

Crash Type: UNKNOWN WRITE
Crash Address: 0x000000000000
Crash State:
  base::LinearHistogram::FactoryGet
  skia::HistogramEnumeration
  SkBaseDevice::LogDrawScaleFactor
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_filter_fuzz_stub&range=387928:387987

Minimized Testcase (0.09 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97YtPYWaUgnoW1y7J-6J0TZHrh95TahstZNmwB8nzDHSUIXFpAY_ufQjsCP0sy9TZMPUVoMZ-xFJL_RWTO3a5dLA-Ef9erzBIEPD_y1UrXnxTG0YgJcxVjvgvbOrDBvB5Y-TGLeyYHr99f0ZM7gjRDK78y2sg?testcase_id=4544429121863680

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 3 by ClusterFuzz, Jul 11 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5296053796732928

Fuzzer: sugoi_filter_fuzzer
Job Type: linux_asan_filter_fuzz_stub_32bit
Platform Id: linux

Crash Type: UNKNOWN WRITE
Crash Address: 0x00000000
Crash State:
  base::LinearHistogram::FactoryGet
  skia::HistogramEnumeration
  SkBaseDevice::LogDrawScaleFactor
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_filter_fuzz_stub_32bit&range=387928:387987

Minimized Testcase (0.09 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96aCMKijMN-ilIaX27kz_vPj-ttQpDKSb6eiOaUwV-r8c7MeuQ75Sq3B2gKmBk5KurBvDXlFn3cRur7oe2Xtz6pHPPsNlZnJ_He9hmOuTxq83x3mOretMw_ya8AQCThGY-5LBMRYkFY5ScQrBj255I17qKgFg?testcase_id=5296053796732928

Filer: kavvaru

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Project Member

Comment 4 by ClusterFuzz, Jul 31 2016

ClusterFuzz has detected this issue as fixed in range 408734:408781.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5296053796732928

Fuzzer: sugoi_filter_fuzzer
Job Type: linux_asan_filter_fuzz_stub_32bit
Platform Id: linux

Crash Type: UNKNOWN WRITE
Crash Address: 0x00000000
Crash State:
  base::LinearHistogram::FactoryGet
  skia::HistogramEnumeration
  SkBaseDevice::LogDrawScaleFactor
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_filter_fuzz_stub_32bit&range=387928:387987
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_filter_fuzz_stub_32bit&range=408734:408781

Minimized Testcase (0.09 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96aCMKijMN-ilIaX27kz_vPj-ttQpDKSb6eiOaUwV-r8c7MeuQ75Sq3B2gKmBk5KurBvDXlFn3cRur7oe2Xtz6pHPPsNlZnJ_He9hmOuTxq83x3mOretMw_ya8AQCThGY-5LBMRYkFY5ScQrBj255I17qKgFg?testcase_id=5296053796732928

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by ClusterFuzz, Jul 31 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 6 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment