New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 650178 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Last visit > 30 days ago
Closed: Sep 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in SkOpPtT::contains

Project Member Reported by ClusterFuzz, Sep 26 2016

Issue description

Components: Internals>Skia
Labels: Findit-for-crash M-55 Te-Logged
Owner: caryclark@chromium.org
Status: Assigned (was: Untriaged)
Skia CL::
https://chromium.googlesource.com/skia/+log/5a9c2f110e4f1a78d9bfedcf708168909706d7fd..cc09372730301be78b9d26c1198db1584622cdd9?pretty=fuller

Possible suspect from the above CL
https://codereview.chromium.org/2357353002

caryclark@ could you please look into this issue if it is related to your change,else please help us in finding the appropriate owner for this issue.

Thnaks,
Project Member

Comment 2 by bugdroid1@chromium.org, Sep 26 2016

Project Member

Comment 3 by bugdroid1@chromium.org, Sep 27 2016

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/528cb1814acc891650c6ca4801d486cee4427878

commit 528cb1814acc891650c6ca4801d486cee4427878
Author: skia-deps-roller <skia-deps-roller@chromium.org>
Date: Tue Sep 27 04:50:14 2016

Roll src/third_party/skia/ 787339e94..6a259bfcc (26 commits).

https://chromium.googlesource.com/skia.git/+log/787339e94278..6a259bfcc80a

$ git log 787339e94..6a259bfcc --date=short --no-merges --format='%ad %ae %s'
2016-09-26 mtklein Revert of My take on SkAlign changes. (patchset #3 id:40001 of https://codereview.chromium.org/2368293002/ )
2016-09-26 reed Revert "replace Arithmetic xfermode with imagefilter"
2016-09-26 ethannicholas Revert of Turned on SkSL->GLSL compiler (patchset #37 id:800001 of https://codereview.chromium.org/2288033003/ )
2016-09-26 mtklein Move undefined-func-template to wont-fix warnings.
2016-09-26 reed replace Arithmetic xfermode with imagefilter
2016-09-26 liyuqian Fix typo
2016-09-26 egdaniel Revert of Fix bufferIndex check in VulkanWindowContext (patchset #1 id:1 of https://codereview.chromium.org/2363353003/ )
2016-09-26 egdaniel Fix bufferIndex check in VulkanWindowContext
2016-09-26 ethannicholas Turned on SkSL->GLSL compiler GOLD_TRYBOT_URL= https://gold.skia.org/search?issue=2288033003
2016-09-26 robertphillips Minor clean up of GrAAConvexTessellator
2016-09-26 borenet Roll recipes
2016-09-26 caryclark allow conic chop to fail
2016-09-26 mtklein Turn on -Wundefined-reinterpret-cast.
2016-09-26 brianosman Tag checkerboard bitmaps as sRGB
2016-09-26 mtklein -Wcomma may be good to go now.
2016-09-26 mtklein My take on SkAlign changes.
2016-09-26 halcanary bin/coverage: a GN version of the coverage script
2016-09-26 borenet Include timestamp in nanobench JSON file name
2016-09-26 caryclark add tiger tests
2016-09-26 mtklein Typo?
2016-09-26 mtklein GN: detect is_clang, use it to switch Clang to warning blacklist.
2016-09-26 mtklein Quiet a -Wcomma warning.
2016-09-26 mtklein beziers: I missed an unsequenced moveTo() pair.
2016-09-26 robertphillips Fix some fuzzer complaints
2016-09-26 mtklein Revert "GN: detect is_clang, use it to switch Clang to warning blacklist."
2016-09-26 halcanary Documentation: fix links

BUG= 650178 

CQ_INCLUDE_TRYBOTS=master.tryserver.blink:linux_precise_blink_rel
TBR=fmalita@google.com

Review-Url: https://codereview.chromium.org/2372943002
Cr-Commit-Position: refs/heads/master@{#421107}

[modify] https://crrev.com/528cb1814acc891650c6ca4801d486cee4427878/DEPS

Status: Fixed (was: Assigned)
Project Member

Comment 5 by ClusterFuzz, Sep 29 2016

ClusterFuzz has detected this issue as fixed in range 421082:421136.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6245443023667200

Fuzzer: afl_skia_pathop_fuzzer
Job Type: afl_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000018
Crash State:
  SkOpPtT::contains
  AddIntersectTs
  OpDebug
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=420614:420693
Fixed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=421082:421136

Minimized Testcase (0.28 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95yN1ZCFnKv5w3mi5oRaDk4tZ5IuFBp3RTmXnHZ0NaCLitcUWIERwP-5Ibdf32goJ592pMpWxWrYkFomPXpVJvIEk6MWqVe66FEYmNBqXsy3QedoV7jT6weu7vz5B_vHV7pzKBifxRB6yHO8nffzBj7Cfgikw?testcase_id=6245443023667200

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 6 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment