Issue metadata
Sign in to add a comment
|
Crash in SuperBlitter::blitH |
||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6667406292549632 Fuzzer: afl_skia_path_fuzzer Job Type: afl_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x615fffff810c Crash State: SuperBlitter::blitH walk_convex_edges sk_fill_path Recommended Security Severity: Medium Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=402185:402404 Minimized Testcase (0.04 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97VCq-8cUuPaWbQKvSecCBfKhVuFUlnHF_uQXgX-Vx70B8L337DTVBiI_8m7sCXw9EqZGbtFffqwxE_yy9Rihiw4voNsU_KQQtYyVg7548PUusagHcFIgL0BO4RYnEQb-BlxAktCRaq4JwEdDfQZi8e3MKvzw?testcase_id=6667406292549632 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Sep 4 2016
,
Sep 4 2016
,
Sep 6 2016
,
Sep 6 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/38994ad4f5c7334d0b2d510f8411674183abc826 commit 38994ad4f5c7334d0b2d510f8411674183abc826 Author: skia-deps-roller <skia-deps-roller@chromium.org> Date: Tue Sep 06 20:50:27 2016 Roll src/third_party/skia/ f54c00e81..6669010af (9 commits). https://chromium.googlesource.com/skia.git/+log/f54c00e817b1..6669010af4e6 $ git log f54c00e81..6669010af --date=short --no-merges --format='%ad %ae %s' 2016-09-06 reed check for null-layer-paint after prev fix to savelayer ops 2016-09-06 msarett Delete SkColorSpace::kUnknown_Named, remove fNamed field 2016-09-06 csmartdalton Improve usage of window rectangles 2016-09-06 brucedawson Work around VS 2015 Update 3 optimizer internal compiler error 2016-09-06 halcanary SkDocument: turn off SK_SUPPORT_LEGACY_DOCUMENT_API 2016-09-06 reed test dont-clip-layer 2016-09-06 caryclark provide safe exit for runaway intersections 2016-09-06 caryclark compare degenerates with tolerance 2016-09-06 bsalomon Update Windows build to use VULKAN_SDK rather than VK_SDK_PATH BUG= 643855 , 643933 , 643665 CQ_INCLUDE_TRYBOTS=master.tryserver.blink:linux_precise_blink_rel TBR=caryclark@google.com Review-Url: https://codereview.chromium.org/2312993002 Cr-Commit-Position: refs/heads/master@{#416722} [modify] https://crrev.com/38994ad4f5c7334d0b2d510f8411674183abc826/DEPS
,
Sep 7 2016
ClusterFuzz has detected this issue as fixed in range 416652:416734. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6667406292549632 Fuzzer: afl_skia_path_fuzzer Job Type: afl_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x615fffff810c Crash State: SuperBlitter::blitH walk_convex_edges sk_fill_path Recommended Security Severity: Medium Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=402185:402404 Fixed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=416652:416734 Minimized Testcase (0.04 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97VCq-8cUuPaWbQKvSecCBfKhVuFUlnHF_uQXgX-Vx70B8L337DTVBiI_8m7sCXw9EqZGbtFffqwxE_yy9Rihiw4voNsU_KQQtYyVg7548PUusagHcFIgL0BO4RYnEQb-BlxAktCRaq4JwEdDfQZi8e3MKvzw?testcase_id=6667406292549632 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Sep 7 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Sep 7 2016
,
Sep 13 2016
,
Sep 14 2016
The following revision refers to this bug: https://skia.googlesource.com/skia.git/+/406e44949c3c766a74e18b49f2f1f4e29f862ba8 commit 406e44949c3c766a74e18b49f2f1f4e29f862ba8 Author: caryclark <caryclark@google.com> Date: Tue Sep 06 15:54:10 2016 compare degenerates with tolerance Conics with very large w values can be approximated with two straight lines. This avoids iterating endlessly in an attempt to create quadratics with unstable numerics. Check to see if the first chop generated a pair of lines within the default point comparison tolerance. R=reed@google.com BUG= 643933 , 643665 GOLD_TRYBOT_URL= https://gold.skia.org/search?issue=2312923002 Review-Url: https://codereview.chromium.org/2312923002 [modify] https://crrev.com/406e44949c3c766a74e18b49f2f1f4e29f862ba8/src/core/SkGeometry.cpp [modify] https://crrev.com/406e44949c3c766a74e18b49f2f1f4e29f862ba8/tests/PathTest.cpp
,
Oct 10 2016
,
Dec 14 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by vakh@chromium.org
, Sep 4 2016Owner: caryclark@google.com
Status: Assigned (was: Untriaged)