New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 648058 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Sep 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in gpu::gles2::TextureAttachment::IsSameAttachment

Project Member Reported by ClusterFuzz, Sep 18 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5833982715625472

Fuzzer: gpu_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  gpu::gles2::TextureAttachment::IsSameAttachment
  gpu::gles2::GLES2DecoderImpl::DoBlitFramebufferCHROMIUM
  gpu::gles2::GLES2DecoderImpl::HandleBlitFramebufferCHROMIUM
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=417985:418093

Minimized Testcase (10.38 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94OCKOwxbNePLycRx3VVWKq2Oo46RQ4tJ-K30ZW9nRBmdyszxy7mKzzC4lD0oYzSrf8tEj852xGwrSEY2P-sesYgm_c6wA9pWA-GimqEp67Jle7TA1l4Xtb_lhr0cwqxRXGZTjVhSAEdQnmEZIT2BiMVY2d0A?testcase_id=5833982715625472

Issue manually filed by: mmoroz

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 

Comment 1 by mmoroz@chromium.org, Sep 18 2016

Cc: kcc@chromium.org kbr@chromium.org aizatsky@chromium.org mmoroz@chromium.org
Components: Internals>GPU>WebGL
Owner: piman@chromium.org
Very similar to  bug 646814 , but this one hasn't been fixed by https://codereview.chromium.org/2347063002

Comment 2 by piman@chromium.org, Sep 19 2016

Cc: cwallez@chromium.org
This should have been fixed by https://codereview.chromium.org/2344273003 (certainly did locally), but I think https://bugs.chromium.org/p/chromium/issues/detail?id=647807 is causing trouble and clusterfuzz can't verify.
Should have it fixed soon.

Comment 4 by vmi...@chromium.org, Sep 27 2016

Cc: piman@chromium.org
Labels: M-55
Owner: cwallez@chromium.org
Status: Assigned (was: Untriaged)

Comment 5 by vmi...@chromium.org, Sep 27 2016

Components: -Internals>GPU>WebGL Internals>GPU>Internals
Shouldn't clusterfuzz be able to verify this is fixed now that there aren't memory allocator conflicts in ANGLE?

Comment 7 by piman@chromium.org, Sep 27 2016

Status: Fixed (was: Assigned)
Yeah, I don't see crashes for this on CF and the report page says fixed. Not sure why CF didn't update this bug.

Comment 8 by mmoroz@google.com, Sep 28 2016

Labels: ClusterFuzz-Wrong
Project Member

Comment 9 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 10 by aarya@google.com, Apr 21 2017

Cc: jaslack@google.com
Labels: -ClusterFuzz-Wrong
We have made a bunch of changes on ClusterFuzz side, so resetting ClusterFuzz-Wrong label.

Sign in to add a comment