Undefined-shift in u8_u16 |
|||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4643757555449856 Fuzzer: libfuzzer_hunspell_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: u8_u16 SuggestMgr::ngram SuggestMgr::ngsuggest Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=400697:402043 Minimized Testcase (0.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94_6PfuoFtfStJuj3l5TVW7QtlukKKuuXJ_T8L80GtZAWuKbKBf3jMi1959f3uYhRDZplk53hz75rgqwsL3hsv_-UBIda6FIpuv2ETFkHbxZvXjxFUIJ2GqiahAJ3QPxsoe3w1XGj3NcNRFpkBMiT1Z3Du5Lw?testcase_id=4643757555449856 Filer: mmoroz See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Jun 30 2016
Not sure why I was assigned this. None of the commits in regression range is mine.
,
Jul 6 2016
ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4643757555449856 Fuzzer: libfuzzer_hunspell_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: u8_u16 SuggestMgr::ngram SuggestMgr::ngsuggest Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=400697:402043 Minimized Testcase (0.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94_6PfuoFtfStJuj3l5TVW7QtlukKKuuXJ_T8L80GtZAWuKbKBf3jMi1959f3uYhRDZplk53hz75rgqwsL3hsv_-UBIda6FIpuv2ETFkHbxZvXjxFUIJ2GqiahAJ3QPxsoe3w1XGj3NcNRFpkBMiT1Z3Du5Lw?testcase_id=4643757555449856 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jul 14 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5410299356381184 Fuzzer: libfuzzer_hunspell_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: u8_u16 SuggestMgr::ngram SuggestMgr::ngsuggest Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=400697:402043 Minimized Testcase (0.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96SzVF1ggpqPTJy7dR28oy2UKzldrIsks72wHXK2S6HqWmryCim1qe8BxL7tqmMkGmHvry9oeQGtdzhHqJmPAamD89yYhotMp-eHfvc25IRzQ7ONahNz8l3E0_nM07LVeJ4-8FOcrQvTNkD8KNy4DvkQacAgw?testcase_id=5410299356381184 Filer: kavvaru See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Jul 29 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6496088236490752 Fuzzer: libfuzzer_hunspell_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: u8_u16 SuggestMgr::ngram SuggestMgr::ngsuggest Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=400697:402043 Minimized Testcase (0.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94gBy-5HhLwhI9fFAdm9_UIJ9xT02mzBesZ7uOKiw4YkXi_1M-qpfHO4_vbTBeFTl-6kEGlr9ehYHrkSbPpS-XgDAVTMpzfMCpngA9jou9JOTscqRUa0XNB5tmQaE-pmvfRc0IIhzvfd5gvOKDqdmzdBeQp-w?testcase_id=6496088236490752 Filer: rnimmagadda See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Jul 29 2016
Suspecting: Author: mmoroz Project: chromium Changelist: https://chromium.googlesource.com/chromium/src//+/cf3e7e2ae4087ed941106aee0411c786dc4f112d Time: Fri Jun 24 11:06:02 2016 File hunspell_fuzzer.cc is changed in this cl (and is part of stack frame #4, "LLVMFuzzerTestOneInput") Minimum distance from crash line to modified line: 3. (file: hunspell_fuzzer.cc, crashed on: 21, modified: 18). @mmoroz: Could you please look into this issue. Thank you.
,
Aug 1 2016
groby@, could you please help to triage this?
,
Aug 24 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/e87c5a27a35c73cc8b099742d914d79d7543deea commit e87c5a27a35c73cc8b099742d914d79d7543deea Author: krb <krb@chromium.org> Date: Wed Aug 24 16:57:21 2016 Changed signed char* to unsigned char*, fuzzer fix Fuzzer reports undefined behavior precisely at the locations where it performs a left shift on a signed char. Changing it to a regular char makes the errors go away. Since the function is doing lots of bit manipulation, a signed char seems inappropriate anyways. All spellcheck tests pass with regular char. The upstream github history (that I could find) shows that it has always been signed, so I couldn't find a reason why it changed, if it ever did. BUG= 620659 , 624348 Review-Url: https://codereview.chromium.org/2263263003 Cr-Commit-Position: refs/heads/master@{#414095} [modify] https://crrev.com/e87c5a27a35c73cc8b099742d914d79d7543deea/third_party/hunspell/google.patch [modify] https://crrev.com/e87c5a27a35c73cc8b099742d914d79d7543deea/third_party/hunspell/src/hunspell/csutil.cxx
,
Aug 25 2016
ClusterFuzz has detected this issue as fixed in range 414068:414117. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6496088236490752 Fuzzer: libfuzzer_hunspell_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: u8_u16 SuggestMgr::ngram SuggestMgr::ngsuggest Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=400697:402043 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=414068:414117 Minimized Testcase (0.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94gBy-5HhLwhI9fFAdm9_UIJ9xT02mzBesZ7uOKiw4YkXi_1M-qpfHO4_vbTBeFTl-6kEGlr9ehYHrkSbPpS-XgDAVTMpzfMCpngA9jou9JOTscqRUa0XNB5tmQaE-pmvfRc0IIhzvfd5gvOKDqdmzdBeQp-w?testcase_id=6496088236490752 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Aug 25 2016
ClusterFuzz has detected this issue as fixed in range 414068:414117. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5410299356381184 Fuzzer: libfuzzer_hunspell_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: u8_u16 SuggestMgr::ngram SuggestMgr::ngsuggest Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=400697:402043 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=414068:414117 Minimized Testcase (0.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96SzVF1ggpqPTJy7dR28oy2UKzldrIsks72wHXK2S6HqWmryCim1qe8BxL7tqmMkGmHvry9oeQGtdzhHqJmPAamD89yYhotMp-eHfvc25IRzQ7ONahNz8l3E0_nM07LVeJ4-8FOcrQvTNkD8KNy4DvkQacAgw?testcase_id=5410299356381184 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Aug 25 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Apr 27 2017
|
|||||||
►
Sign in to add a comment |
|||||||
Comment 1 by mmoroz@chromium.org
, Jun 29 2016Components: UI>Browser>Spellcheck
Owner: phajdan.jr@chromium.org