Crash in t |
|||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5904775657029632 Fuzzer: libfuzzer_skia_pathop_fuzzer Job Type: libfuzzer_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: t step SkOpSegment::nextChase Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=401619:401727 Minimized Testcase (0.47 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96K2Dw3UZRdK85txtrLoWf6wGEE0TI3puRrJBXsiZQZ8R461u4_M6YCCViBJx7OPKi5Yt_DyieFTkKiX2p4d_eSk8qpXTrOJ43kmL5yFkiBmo2WFPhrVMSh6LHQpSA3yw4gys6jybiI1ly5wXniyPTbsXCCsA?testcase_id=5904775657029632 Filer: mmoroz See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Jun 29 2016
,
Jun 29 2016
The following revision refers to this bug: https://skia.googlesource.com/skia.git/+/343382e3acc8369f7bd4328e7c807255b5776fe5 commit 343382e3acc8369f7bd4328e7c807255b5776fe5 Author: caryclark <caryclark@google.com> Date: Wed Jun 29 15:18:38 2016 fix fuzz test that exceeds numeric limit The extreme values here exceed an internal test that expects computed numbers to be less than MAX_FLT. Use MAX_DBL instead. R=mmoroz@chromium.org TBR=reed@google.com BUG= 624346 GOLD_TRYBOT_URL= https://gold.skia.org/search?issue=2103903004 Review-Url: https://codereview.chromium.org/2103903004 [modify] https://crrev.com/343382e3acc8369f7bd4328e7c807255b5776fe5/src/pathops/SkOpSegment.cpp [modify] https://crrev.com/343382e3acc8369f7bd4328e7c807255b5776fe5/src/pathops/SkPathOpsTSect.h [modify] https://crrev.com/343382e3acc8369f7bd4328e7c807255b5776fe5/tests/PathOpsOpTest.cpp
,
Jun 29 2016
,
Jun 30 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/a558e00247735ab49611023dcf02c73a620385d8 commit a558e00247735ab49611023dcf02c73a620385d8 Author: skia-deps-roller <skia-deps-roller@chromium.org> Date: Thu Jun 30 00:33:35 2016 Roll src/third_party/skia/ 26726d1ca..fc5b70a8e (16 commits). https://chromium.googlesource.com/skia.git/+log/26726d1ca7ed..fc5b70a8e427 $ git log 26726d1ca..fc5b70a8e --date=short --no-merges --format='%ad %ae %s' 2016-06-29 benjaminwagner Revert of Better encapsulate oval/rrect batchs. (patchset #3 id:40001 of https://codereview.chromium.org/2104423003/ ) 2016-06-29 reed add SK_SUPPORT_PRECHECK_CLIPRECT experiment for clipRect 2016-06-29 bsalomon Better encapsulate oval/rrect batchs. GOLD_TRYBOT_URL= https://gold.skia.org/search?issue=2104423003 2016-06-29 caryclark fix asan bug triggered by pathops fuzz tests 2016-06-29 robertphillips Move dump of batches to be after the forwardCombine call in prepareBatches 2016-06-29 reed add short-desc 2016-06-29 caryclark fix another pathops fuzz bug 2016-06-29 robertphillips Add Annotations to old debugger GOLD_TRYBOT_URL= https://gold.skia.org/search?issue=2110083002 2016-06-29 benjaminwagner Disable PathOpsFailOp test for Bazel ASAN test, because there are double->float cast overflows in PathOps code. 2016-06-29 caryclark fix fuzz test that exceeds numeric limit 2016-06-29 halcanary SkPDF: always assume SkStreamAsset behaves as specified 2016-06-29 benjaminwagner Check for empty output in adb_wait_for_charge. 2016-06-29 robertphillips Dump batch bounds and scissor rect 2016-06-29 halcanary SkPDF: SkPDFStream takes only SkStreamAsset 2016-06-29 martina.kollarova Remove unnecessary includes in src/pdf/ 2016-06-28 reed add annotations to debugger BUG= 624351 , 624346 ,None CQ_INCLUDE_TRYBOTS=tryserver.blink:linux_blink_rel TBR=benjaminwagner@google.com Review-Url: https://codereview.chromium.org/2111723002 Cr-Commit-Position: refs/heads/master@{#403032} [modify] https://crrev.com/a558e00247735ab49611023dcf02c73a620385d8/DEPS
,
Jul 1 2016
ClusterFuzz has detected this issue as fixed in range 402867:403103. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5904775657029632 Fuzzer: libfuzzer_skia_pathop_fuzzer Job Type: libfuzzer_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: t step SkOpSegment::nextChase Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=401619:401727 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=402867:403103 Minimized Testcase (0.47 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96K2Dw3UZRdK85txtrLoWf6wGEE0TI3puRrJBXsiZQZ8R461u4_M6YCCViBJx7OPKi5Yt_DyieFTkKiX2p4d_eSk8qpXTrOJ43kmL5yFkiBmo2WFPhrVMSh6LHQpSA3yw4gys6jybiI1ly5wXniyPTbsXCCsA?testcase_id=5904775657029632 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jul 1 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||
►
Sign in to add a comment |
|||||
Comment 1 by mmoroz@chromium.org
, Jun 29 2016Components: Internals>Skia
Owner: reed@chromium.org