New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 648526 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Email to this user bounced
Closed: Sep 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in SkLineClipper::IntersectLine

Project Member Reported by ClusterFuzz, Sep 20 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6496446155325440

Fuzzer: libfuzzer_skia_path_fuzzer
Job Type: libfuzzer_chrome_asan_debug
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x03e900006e0a
Crash State:
  SkLineClipper::IntersectLine
  SkScan::AntiHairLineRgn
  hair_quad
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=400450:400546

Minimized Testcase (0.04 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95SgMOB_RJNEYT6na7WlEPyepnfcWSLjkZPVL88Tc3jGeq6Nobsj3cspU--iYm3AFk2CtNUUWP9p3N31Ttdc3WZh1RvfTNpC5S9ZiOxx_H9zNO7Kg7_VPOrp8MNlnUpcAbysTzVRUnob2WP9QdNuKhmi_M-ig?testcase_id=6496446155325440

Issue manually filed by: kavvaru

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Components: Internals>Skia
Labels: M-54 Findit-for-crash Te-Logged
Owner: reed@chromium.org
Status: Assigned (was: Untriaged)
Findit tool information
=======================
	Git blame below is NOT necessarily who introduced the crash nor the owner for it. Please check the code before assigning to anyone.(No CL in the regression range changed the crashing files.)

Author: reed@android.com
Project: chromium-skia
Changelist: https://chromium.googlesource.com/skia.git/+/a3d901099d7d295cd7d9df4114e874d9ccfff447
Time: Mon Nov 30 12:48:33 2009
The CL last changed line 141 of file SkLineClipper.cpp, which is stack frame 1.

Author: reed
Project: chromium-skia
Changelist: https://chromium.googlesource.com/skia.git/+/5dc6b7d1a8bc591d62366ff83c434ff74f3e10fc
Time: Tue Apr 14 17:40:44 2015
The CL last changed line 561 of file SkScan_Antihair.cpp, which is stack frame 2.

Author: reed
Project: chromium-skia
Changelist: https://chromium.googlesource.com/skia.git/+/6983f66d8b3a489133b751e2cef03e72a03bfeae
Time: Thu Apr 16 01:23:03 2015
The CL last changed line 240 of file SkScan_Hairline.cpp, which is stack frame 3.

Author: caryclark
Project: chromium-skia
Changelist: https://chromium.googlesource.com/skia.git/+/4cba202b7162fb5f364235dd29f0bdbd53a8e33c
Time: Thu May 12 14:07:05 2016
The CL last changed line 288 of file SkScan_Hairline.cpp, which is stack frame 4.

Author: caryclark
Project: chromium-skia
Changelist: https://chromium.googlesource.com/skia.git/+/4cba202b7162fb5f364235dd29f0bdbd53a8e33c
Time: Thu May 12 14:07:05 2016
The CL last changed line 557 of file SkScan_Hairline.cpp, which is stack frame 5.

Author: caryclark
Project: chromium-skia
Changelist: https://chromium.googlesource.com/skia.git/+/2028d7ff744c36855ed36d602e3e050e9f18ec9f
Time: Wed Dec 09 22:04:46 2015
The CL last changed line 606 of file SkScan_Hairline.cpp, which is stack frame 6.

Suspected Project: chromium-skia
Suspected Component: Internals>Skia
======================
From the above information the changes made to the file "SkScan_Hairline.cpp" from frame 3 is more related to it.

reed@ could you please look into this issue if it is related to your change,else please help us in finding the appropriate owner for this issue.

Thanks,
Project Member

Comment 2 by ClusterFuzz, Sep 23 2016

ClusterFuzz has detected this issue as fixed in range 420262:420312.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6496446155325440

Fuzzer: libfuzzer_skia_path_fuzzer
Job Type: libfuzzer_chrome_asan_debug
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x03e900006e0a
Crash State:
  SkLineClipper::IntersectLine
  SkScan::AntiHairLineRgn
  hair_quad
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=400450:400546
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=420262:420312

Minimized Testcase (0.04 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95SgMOB_RJNEYT6na7WlEPyepnfcWSLjkZPVL88Tc3jGeq6Nobsj3cspU--iYm3AFk2CtNUUWP9p3N31Ttdc3WZh1RvfTNpC5S9ZiOxx_H9zNO7Kg7_VPOrp8MNlnUpcAbysTzVRUnob2WP9QdNuKhmi_M-ig?testcase_id=6496446155325440

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 3 by ClusterFuzz, Sep 23 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 4 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment