New issue
Advanced search Search tips

Issue 627342 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 627387
Owner:
Closed: Jul 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in SkSpecialImage_Raster::SkSpecialImage_Raster

Project Member Reported by ClusterFuzz, Jul 12 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4639891426377728

Fuzzer: sugoi_filter_fuzzer
Job Type: linux_asan_filter_fuzz_stub_32bit
Platform Id: linux

Crash Type: UNKNOWN WRITE
Crash Address: 0x00000004
Crash State:
  SkSpecialImage_Raster::SkSpecialImage_Raster
  SkSpecialImage::MakeFromRaster
  SkSpecialSurface_Raster::onMakeImageSnapshot
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_filter_fuzz_stub_32bit&range=381909:382014

Minimized Testcase (0.07 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94rZG3T8DIvb4q61ArOzEhiExCPwcCYhbIlxEV1yqmielKmHoA_f1EhoRLbza6ZeCG7F9r9TdJfeCuu7LoQYnzZbu_aLI6ac3Wp_aJmCMBA7qZGtDCoYSK_4U1-yKoi8hhrgiBAu6QM2nM3zjh8u7nZ7i3Ybw?testcase_id=4639891426377728

Filer: nyerramilli

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: nyerramilli@chromium.org
Components: Tools>Test>FindIt>CorrectResult
Labels: findit-for-crash M-52
Owner: robertphillips@chromium.org
Status: Assigned (was: Available)
based on Findit results, assigning to robertphillips@ - Could you please take a look at the issue and assign it to concerned developer if your changes are not responsible?

Findit Result:
----------------
Suspected CLs	The result is a list of CLs that change the crashed files.

Author: robertphillips
Project: chromium-skia
Changelist: https://chromium.googlesource.com/skia.git/+/37bd7c3aca66697fff2db79c21771a0b3cbe3b4c
Time: Thu Mar 17 21:31:39 2016
Lines 58-59, 84-85, 94-102 of file SkSpecialSurface.cpp which potentially caused crash are changed in this cl (frame #5, "SkSpecialSurface_Raster::onMakeImageSnapshot"; frame #6, "SkSpecialSurface::makeImageSnapshot").

Lines 61-66, 74-84, 106-114, 135, 428 of file SkSpecialImage.cpp which potentially caused crash are changed in this cl (frame #0, "SkSpecialImage"; frame #4, "SkSpecialImage::MakeFromRaster").
Minimum distance from crash line to modified line: 0. (file: SkSpecialSurface.cpp, crashed on: 58, modified: 58).

Author: robertphillips
Project: chromium-skia
Changelist: https://chromium.googlesource.com/skia.git/+/05849018c85403a34b88819db1c4bcf713b70a2b
Time: Thu Mar 17 22:15:58 2016
Lines 61-82 of file SkSpecialImage.cpp which potentially caused crash are changed in this cl (frame #0, "SkSpecialImage").
Minimum distance from crash line to modified line: 0. (file: SkSpecialImage.cpp, crashed on: 61, modified: 61).

Author: robertphillips
Project: chromium-skia
Changelist: https://chromium.googlesource.com/skia.git/+/83c17fa56b23159166394cb3feb431ffafbbab48
Time: Fri Mar 18 15:14:27 2016
Lines 61-82 of file SkSpecialImage.cpp which potentially caused crash are changed in this cl (frame #0, "SkSpecialImage").
Minimum distance from crash line to modified line: 0. (file: SkSpecialImage.cpp, crashed on: 61, modified: 61).

Suspected Project: chromium-skia
Suspected Component: Internals>Skia


Mergedinto: 627387
Status: Duplicate (was: Assigned)
Project Member

Comment 3 by ClusterFuzz, Sep 17 2016

ClusterFuzz has detected this issue as fixed in range 411299:411328.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4639891426377728

Fuzzer: sugoi_filter_fuzzer
Job Type: linux_asan_filter_fuzz_stub_32bit
Platform Id: linux

Crash Type: UNKNOWN WRITE
Crash Address: 0x00000004
Crash State:
  SkSpecialImage_Raster::SkSpecialImage_Raster
  SkSpecialImage::MakeFromRaster
  SkSpecialSurface_Raster::onMakeImageSnapshot
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_filter_fuzz_stub_32bit&range=381909:382014
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_filter_fuzz_stub_32bit&range=411299:411328

Minimized Testcase (0.07 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94rZG3T8DIvb4q61ArOzEhiExCPwcCYhbIlxEV1yqmielKmHoA_f1EhoRLbza6ZeCG7F9r9TdJfeCuu7LoQYnzZbu_aLI6ac3Wp_aJmCMBA7qZGtDCoYSK_4U1-yKoi8hhrgiBAu6QM2nM3zjh8u7nZ7i3Ybw?testcase_id=4639891426377728

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
This issue is not fixed. The fuzzer is still being run with: allocator_may_return_null=1
Project Member

Comment 5 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment