Undefined-shift in little2_prologTok |
|||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5043878801702912 Fuzzer: libfuzzer_expat_xml_parse_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: little2_prologTok prologProcessor XML_ParseBuffer Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=397275:397295 Minimized Testcase (0.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv963lAfsjq-2OFSvcgTwCrb6moMoY5X_VOCc7z9lOdsXbdvz6Jy9jqIu0964Hy1HVBYcXvppze2TORh52s83e-ZH1OPM-_nvM8dgklv4tq6rXxW39MZkJTiLcsLrvNpSQULRwX6UAagoUJ0gDMYa35ZNOgqI7w?testcase_id=5043878801702912 Filer: kavvaru See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Jul 14 2016
Moving this nonessential bug to the next milestone. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jul 14 2016
My change simply made the fuzzer effective. It doesn't change the target library but simply enabled our infrastructure to uncover the issue.
,
Jul 14 2016
Max, is there anyone responsible for expat?
,
Jul 14 2016
,
Jul 15 2016
No, we don't have anyone responsible for expat :(
,
Jul 15 2016
Moreover, I cannot find any usage of expat in the repo: https://cs.chromium.org/search/?q=%22expat.h%3E%22&sq=package:chromium&type=cs - these files should be using a system version May be only this one: https://cs.chromium.org/chromium/src/third_party/webrtc/libjingle/xmllite/BUILD.gn?q=expat+file:%5Esrc/third_party/webrtc/libjingle/xmllite/&sq=package:chromium&l=40&dr=C
,
Jul 15 2016
tommi@, since you are one of the OWNERS of webrtc and webrtc/libjingle, and given that webrtc/libjingle looks like the only usage of //third_party/expat, let me assign this to you. My suggestion is: If we need to have expat in the repo, we should assign an owner for that. Otherwise it seems to be a good chance to get rid of expat.
,
Jul 15 2016
Peter - can you take a look?
,
Aug 13 2016
ClusterFuzz has detected this issue as fixed in range 411369:411551. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5043878801702912 Fuzzer: libfuzzer_expat_xml_parse_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: little2_prologTok prologProcessor XML_ParseBuffer Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=397275:397295 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=411369:411551 Minimized Testcase (0.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv963lAfsjq-2OFSvcgTwCrb6moMoY5X_VOCc7z9lOdsXbdvz6Jy9jqIu0964Hy1HVBYcXvppze2TORh52s83e-ZH1OPM-_nvM8dgklv4tq6rXxW39MZkJTiLcsLrvNpSQULRwX6UAagoUJ0gDMYa35ZNOgqI7w?testcase_id=5043878801702912 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Aug 13 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||
►
Sign in to add a comment |
|||||||||
Comment 1 by kavvaru@chromium.org
, Jul 14 2016Labels: Te-Logged M-53
Owner: aizatsky@chromium.org
Status: Assigned (was: Available)