Crash in span |
||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5049479277576192 Fuzzer: libfuzzer_skia_pathop_fuzzer Job Type: libfuzzer_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000010 Crash State: span SkOpCoincidence::addOrOverlap SkOpCoincidence::addIfMissing Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=411575:411719 Minimized Testcase (0.43 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94yipmc1NSmbJ_lDra3i3SDm90977VJJ4RPleu6KuD9PcELSP4oH841XbXJ3EOp3BFUGy1tGpV16scQIHjncfMSjg8KCUUf-s0ilRBSShj5Ect5gHHw-IfQ4_rqHZEG304Y_a5Jlxks7nV2SqHUAGW5-J9TEA?testcase_id=5049479277576192 Issue manually filed by: mummareddy See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Aug 16 2016
I have not been able to repro this with ToT. Can you check my steps, please? gn gen out/libfuzzer_asan '--args=use_libfuzzer=true is_asan=true enable_nacl=false proprietary_codecs=true' ninja -C out/libfuzzer_asan skia_pathop_fuzzer ./out/libfuzzer_asan/skia_pathop_fuzzer ~/Downloads/fuzz-3-skia_pathop_fuzzer
,
Aug 16 2016
nevermind, I wasn't at ToT as I thought
,
Aug 16 2016
The following revision refers to this bug: https://skia.googlesource.com/skia.git/+/a1b42d91a5726683d7933b81a6e00ed28649e7ed commit a1b42d91a5726683d7933b81a6e00ed28649e7ed Author: caryclark <caryclark@google.com> Date: Tue Aug 16 17:25:29 2016 fix fuzz bug TBR=reed@google.com BUG= 637968 , 638002 GOLD_TRYBOT_URL= https://gold.skia.org/search?issue=2250573003 Review-Url: https://codereview.chromium.org/2250573003 [modify] https://crrev.com/a1b42d91a5726683d7933b81a6e00ed28649e7ed/src/pathops/SkOpCoincidence.cpp [modify] https://crrev.com/a1b42d91a5726683d7933b81a6e00ed28649e7ed/src/pathops/SkPathOpsTSect.h [modify] https://crrev.com/a1b42d91a5726683d7933b81a6e00ed28649e7ed/tests/PathOpsOpTest.cpp
,
Aug 16 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/99b207c94f0b9697465f1249d05e1f89660ceb95 commit 99b207c94f0b9697465f1249d05e1f89660ceb95 Author: skia-deps-roller <skia-deps-roller@chromium.org> Date: Tue Aug 16 21:32:54 2016 Roll src/third_party/skia/ af68fa11e..8fd23a86d (10 commits). https://chromium.googlesource.com/skia.git/+log/af68fa11ed61..8fd23a86d0d1 $ git log af68fa11e..8fd23a86d --date=short --no-merges --format='%ad %ae %s' 2016-08-16 bungeman Remove SkPreprocessorSeq.h and SkTypedEnum.h. 2016-08-16 halcanary SkPDF: Font names need escaping 2016-08-16 halcanary SkPDF: eliminate SkPDFCIDfont class 2016-08-16 caryclark fix fuzz bug 2016-08-16 halcanary SkPDF: SkPDFFont class changes 2016-08-16 mtklein SkLiteDL: remove freelisting, add reset() and SKLITEDL_PAGE knob. 2016-08-16 mtklein GN: add extra_cflags et al. 2016-08-16 msarett Add onDrawBitmapLattice(), avoid unnecessary bitmap->image copy 2016-08-16 robertphillips Update ComputeBlurredRRectParams to compute all the parameters needed for occluded blurred rrect ninepatch draws 2016-08-16 mtklein 32-bit fast hash, tidy up murmur3 a bit BUG= 637968 , 638002 CQ_INCLUDE_TRYBOTS=master.tryserver.blink:linux_precise_blink_rel TBR=robertphillips@google.com Review-Url: https://codereview.chromium.org/2245373004 Cr-Commit-Position: refs/heads/master@{#412342} [modify] https://crrev.com/99b207c94f0b9697465f1249d05e1f89660ceb95/DEPS
,
Aug 17 2016
ClusterFuzz has detected this issue as fixed in range 412260:412422. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5049479277576192 Fuzzer: libfuzzer_skia_pathop_fuzzer Job Type: libfuzzer_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000010 Crash State: span SkOpCoincidence::addOrOverlap SkOpCoincidence::addIfMissing Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=411575:411719 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=412260:412422 Minimized Testcase (0.43 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94yipmc1NSmbJ_lDra3i3SDm90977VJJ4RPleu6KuD9PcELSP4oH841XbXJ3EOp3BFUGy1tGpV16scQIHjncfMSjg8KCUUf-s0ilRBSShj5Ect5gHHw-IfQ4_rqHZEG304Y_a5Jlxks7nV2SqHUAGW5-J9TEA?testcase_id=5049479277576192 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Aug 17 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Aug 25 2016
Re-oped this as Clusterfuzz has detected this crash again impacting to Head.
,
Aug 25 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5413906564775936 Fuzzer: libfuzzer_skia_pathop_fuzzer Job Type: libfuzzer_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000010 Crash State: span SkOpCoincidence::addOrOverlap SkOpCoincidence::addIfMissing Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=405990:406128 Minimized Testcase (0.41 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96IuNTusjUubNeVDEXGqHy4IK_SWu8lkcTDC_7U7Y98GxBhirvBGn-auoo6zEirozcbc5dZSasXM9ouUWPrfpS0A_mZQOtNYpS2OIENAdKWJXQaudbrqXchHJsc0pyNGEKj1YSQqWT28PMvhb2KWbyX83jRVA?testcase_id=5413906564775936 Issue manually filed by: durga.behera See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Aug 25 2016
ClusterFuzz has detected this issue as fixed in range 414042:414068. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5413906564775936 Fuzzer: libfuzzer_skia_pathop_fuzzer Job Type: libfuzzer_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000010 Crash State: span SkOpCoincidence::addOrOverlap SkOpCoincidence::addIfMissing Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=405990:406128 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=414042:414068 Minimized Testcase (0.41 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96IuNTusjUubNeVDEXGqHy4IK_SWu8lkcTDC_7U7Y98GxBhirvBGn-auoo6zEirozcbc5dZSasXM9ouUWPrfpS0A_mZQOtNYpS2OIENAdKWJXQaudbrqXchHJsc0pyNGEKj1YSQqWT28PMvhb2KWbyX83jRVA?testcase_id=5413906564775936 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Aug 25 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Sep 18 2017
We have made a bunch of changes on ClusterFuzz side, so resetting ClusterFuzz-Wrong label. |
||||||||
►
Sign in to add a comment |
||||||||
Comment 1 by mummare...@chromium.org
, Aug 15 2016Labels: M-54 Findit-for-crash Te-Logged
Owner: caryclark@chromium.org
Status: Assigned (was: Untriaged)