New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 642355 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Email to this user bounced
Closed: Jan 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Regression



Sign in to add a comment

Crash in backward_insert_edge_based_on_x

Project Member Reported by ClusterFuzz, Aug 30 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6671679797592064

Fuzzer: libfuzzer_skia_path_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000010
Crash State:
  backward_insert_edge_based_on_x
  walk_edges
  sk_fill_path
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=415048:415184

Minimized Testcase (0.12 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94dRO9aaM-f62Ek6O07VtRd9adoVO0MpoVTJEof2q17Jbv7OvRVEL1rjhFdD0eeF6OYeP3GwoX9rX_BDNieE-_7Nzjzmr-tK3wFg5kQh2U_GIJZ4LLzyDDsKLgAWBhGvnXJJFtp9vSooifyUV7o72-p82hUBA?testcase_id=6671679797592064

Issue manually filed by: msrchandra

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Components: Internals>Skia
Labels: -Type-Bug findit-wrong Te-Logged Type-Bug-Regression
Owner: reed@chromium.org
Status: Assigned (was: Untriaged)
Find it did not provide any possible suspect. Providing the data for internal purpose.
Suspected CLs	Git blame below is NOT necessarily who introduced the crash nor the owner for it. Please check the code before assigning to anyone.(No CL in the regression range changed the crashing files.)

Author: reed
Project: chromium-skia
Changelist: https://chromium.googlesource.com/skia.git/+/01d3319b67b1ad404006a0026803efc1573f4570
Time: Sat Feb 07 20:18:41 2015
The CL last changed line 55 of file SkScan_Path.cpp, which is stack frame 0.

Author: reed@android.com
Project: chromium-skia
Changelist: https://chromium.googlesource.com/skia.git/+/8a1c16ff38322f0210116fa7293eb8817c7e477e
Time: Wed Dec 17 15:59:43 2008
The CL last changed line 194 of file SkScan_Path.cpp, which is stack frame 1.

Author: reed
Project: chromium-skia
Changelist: https://chromium.googlesource.com/skia.git/+/01d3319b67b1ad404006a0026803efc1573f4570
Time: Sat Feb 07 20:18:41 2015
The CL last changed line 514 of file SkScan_Path.cpp, which is stack frame 2.

Author: reed@google.com
Project: chromium-skia
Changelist: https://chromium.googlesource.com/skia.git/+/1501803e93a9c76b4632086d05c2813cb475db27
Time: Mon Jul 11 12:21:30 2011
The CL last changed line 670 of file SkScan_Path.cpp, which is stack frame 3.

Author: reed@google.com
Project: chromium-skia
Changelist: https://chromium.googlesource.com/skia.git/+/1ba7137fc0dcace0c1be1367fe977202c63746ba
Time: Wed Oct 12 20:42:05 2011
The CL last changed line 741 of file SkScan_AntiPath.cpp, which is stack frame 4.

Author: reed
Project: chromium-skia
Changelist: https://chromium.googlesource.com/skia.git/+/82595b6fa4733e1525f357bdcac22db058790550
Time: Tue May 10 00:48:46 2016
The CL last changed line 1100 of file SkDraw.cpp, which is stack frame 5.

Author: reed
Project: chromium-skia
Changelist: https://chromium.googlesource.com/skia.git/+/82595b6fa4733e1525f357bdcac22db058790550
Time: Tue May 10 00:48:46 2016
The CL last changed line 1193 of file SkDraw.cpp, which is stack frame 6.

Suspected Project: chromium-skia
Suspected Component: Internals>Skia

Assigning to the owner who already worked on similar issue.

@reed -- Could you please look into the issue, pardon me if it has nothing to do with your changes.
Thank You.

Project Member

Comment 2 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 3 by ClusterFuzz, Jan 28 2017

ClusterFuzz has detected this issue as fixed in range 446675:446784.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6671679797592064

Fuzzer: libfuzzer_skia_path_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000010
Crash State:
  backward_insert_edge_based_on_x
  walk_edges
  sk_fill_path
  
Sanitizer: address (ASAN)

Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=415048:415184
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=446675:446784

Minimized Testcase (0.12 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96g5lfgdZgCh1Q1vd5LOWIp8GTph0w6Yk_4BMhTN7tmBW5kOPI8SRkuKwp5LtjC_5EecGA3dqAeOucaTgFky9ZswHQeC3aoTHnRq0mBBNTnVuA6hPOLtPAZycwBbrzJpg09w8DTAlbMYj-YGoQLmJ5I7Szg3bgBfrtwkFFyQNFa9sDRIDFvNSVultP-QnGr0I9BA4AE76qkvf610jlx4Web1QgZJlJoZQwduyYvJt7V08Z8UZ5DoNsHmNkVFsbElOccN6Ai5eIXDRB_7L3JkujSjwu0IUZnWzUXvt9hxQn2QzyZFNgi6zo436pvBziu4haxfpVeYIOjftIRD_VbdlfNdbb1b9GU3hrjTo0E6ZwNq3_IQvw?testcase_id=6671679797592064

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 4 by ClusterFuzz, Jan 28 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 6671679797592064 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment