Integer-overflow in SkXfermodeImageFilter::filterImageGPU |
||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4957986734997504 Fuzzer: inferno_twister Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: SkXfermodeImageFilter::filterImageGPU SkXfermodeImageFilter::onFilterImage SkImageFilter::filterImage Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=398502:398570 Minimized Testcase (129.69 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96t4Fz91X3g2ghzqXh9q0PRq6-pVG1f7gSk04OWjTKEIAUPK8394cbythhE-f0dFCtZd9QVeztwVkcLekOuJFi3dKoS_jQhXh6vr03Q-YTubW5tMqdRqsbDP1yakbh55pq-fyRhPkAgVlmI8mFop6cNIVbqMDK3TPLv6BV6YHYjkNCtrvM?testcase_id=4957986734997504 Issue manually filed by: nyerramilli See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Aug 9 2016
,
Aug 17 2016
,
Aug 17 2016
The following revision refers to this bug: https://skia.googlesource.com/skia.git/+/d092ffd5a89906ced1387b41c224ae7d9446ff0f commit d092ffd5a89906ced1387b41c224ae7d9446ff0f Author: robertphillips <robertphillips@google.com> Date: Wed Aug 17 16:28:59 2016 Kick the can down the road a bit w.r.t. fuzzer complaint BUG= 635787 GOLD_TRYBOT_URL= https://gold.skia.org/search?issue=2247033006 Review-Url: https://codereview.chromium.org/2247033006 [modify] https://crrev.com/d092ffd5a89906ced1387b41c224ae7d9446ff0f/src/effects/SkXfermodeImageFilter.cpp
,
Aug 17 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/8a501196b86e2c17e53fc2c76188e803d4f882e4 commit 8a501196b86e2c17e53fc2c76188e803d4f882e4 Author: skia-deps-roller <skia-deps-roller@chromium.org> Date: Wed Aug 17 17:32:28 2016 Roll src/third_party/skia/ d24ee1419..8d3f92a92 (5 commits). https://chromium.googlesource.com/skia.git/+log/d24ee1419f17..8d3f92a92be7 $ git log d24ee1419..8d3f92a92 --date=short --no-merges --format='%ad %ae %s' 2016-08-17 csmartdalton Make GrReducedClip's gen ID only apply to the element list 2016-08-17 robertphillips Kick the can down the road a bit w.r.t. fuzzer complaint 2016-08-17 bsalomon Fix tile bitmap code in SkGpuDevice to compute correct local coords. 2016-08-17 bsalomon Minor cleanup of GP classes in GrOvalRenderer 2016-08-17 msarett Modify SkPngCodec to recognize 565 images from the sBIT chunk BUG= 635787 CQ_INCLUDE_TRYBOTS=master.tryserver.blink:linux_precise_blink_rel TBR=robertphillips@google.com Review-Url: https://codereview.chromium.org/2251113002 Cr-Commit-Position: refs/heads/master@{#412575} [modify] https://crrev.com/8a501196b86e2c17e53fc2c76188e803d4f882e4/DEPS
,
Aug 18 2016
ClusterFuzz has detected this issue as fixed in range 412570:412592. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4957986734997504 Fuzzer: inferno_twister Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: SkXfermodeImageFilter::filterImageGPU SkXfermodeImageFilter::onFilterImage SkImageFilter::filterImage Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=398502:398570 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=412570:412592 Minimized Testcase (129.69 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96t4Fz91X3g2ghzqXh9q0PRq6-pVG1f7gSk04OWjTKEIAUPK8394cbythhE-f0dFCtZd9QVeztwVkcLekOuJFi3dKoS_jQhXh6vr03Q-YTubW5tMqdRqsbDP1yakbh55pq-fyRhPkAgVlmI8mFop6cNIVbqMDK3TPLv6BV6YHYjkNCtrvM?testcase_id=4957986734997504 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Aug 18 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Oct 18 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||||
►
Sign in to add a comment |
||||||
Comment 1 by nyerramilli@chromium.org
, Aug 9 2016Components: Tools>Test>FindIt>WrongResult
Labels: findit-wrong Te-Logged M-53
Owner: bsalomon@chromium.org
Status: Assigned (was: Untriaged)