Crash in SkOpPtT::contains |
|||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6245443023667200 Fuzzer: afl_skia_pathop_fuzzer Job Type: afl_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000018 Crash State: SkOpPtT::contains AddIntersectTs OpDebug Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=420614:420693 Minimized Testcase (0.28 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95yN1ZCFnKv5w3mi5oRaDk4tZ5IuFBp3RTmXnHZ0NaCLitcUWIERwP-5Ibdf32goJ592pMpWxWrYkFomPXpVJvIEk6MWqVe66FEYmNBqXsy3QedoV7jT6weu7vz5B_vHV7pzKBifxRB6yHO8nffzBj7Cfgikw?testcase_id=6245443023667200 Issue manually filed by: kavvaru See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Sep 26 2016
The following revision refers to this bug: https://skia.googlesource.com/skia.git/+/414c4295f951d43068666b6294df15b2fd2ba85c commit 414c4295f951d43068666b6294df15b2fd2ba85c Author: caryclark <caryclark@google.com> Date: Mon Sep 26 18:03:54 2016 allow conic chop to fail Fuzzy values may cause the conic chop to fail. Check to see if the values are all finite, and require the caller to do the same. R=reed@google.com BUG= 650178 GOLD_TRYBOT_URL= https://gold.skia.org/search?issue=2368993002 Review-Url: https://codereview.chromium.org/2368993002 [modify] https://crrev.com/414c4295f951d43068666b6294df15b2fd2ba85c/gm/beziereffects.cpp [modify] https://crrev.com/414c4295f951d43068666b6294df15b2fd2ba85c/samplecode/SampleAAGeometry.cpp [modify] https://crrev.com/414c4295f951d43068666b6294df15b2fd2ba85c/src/core/SkGeometry.cpp [modify] https://crrev.com/414c4295f951d43068666b6294df15b2fd2ba85c/src/core/SkGeometry.h [modify] https://crrev.com/414c4295f951d43068666b6294df15b2fd2ba85c/src/core/SkPathMeasure.cpp [modify] https://crrev.com/414c4295f951d43068666b6294df15b2fd2ba85c/src/gpu/batches/GrAAHairLinePathRenderer.cpp [modify] https://crrev.com/414c4295f951d43068666b6294df15b2fd2ba85c/src/pathops/SkOpEdgeBuilder.cpp [modify] https://crrev.com/414c4295f951d43068666b6294df15b2fd2ba85c/tests/PathOpsConicIntersectionTest.cpp [modify] https://crrev.com/414c4295f951d43068666b6294df15b2fd2ba85c/tests/PathOpsOpTest.cpp
,
Sep 27 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/528cb1814acc891650c6ca4801d486cee4427878 commit 528cb1814acc891650c6ca4801d486cee4427878 Author: skia-deps-roller <skia-deps-roller@chromium.org> Date: Tue Sep 27 04:50:14 2016 Roll src/third_party/skia/ 787339e94..6a259bfcc (26 commits). https://chromium.googlesource.com/skia.git/+log/787339e94278..6a259bfcc80a $ git log 787339e94..6a259bfcc --date=short --no-merges --format='%ad %ae %s' 2016-09-26 mtklein Revert of My take on SkAlign changes. (patchset #3 id:40001 of https://codereview.chromium.org/2368293002/ ) 2016-09-26 reed Revert "replace Arithmetic xfermode with imagefilter" 2016-09-26 ethannicholas Revert of Turned on SkSL->GLSL compiler (patchset #37 id:800001 of https://codereview.chromium.org/2288033003/ ) 2016-09-26 mtklein Move undefined-func-template to wont-fix warnings. 2016-09-26 reed replace Arithmetic xfermode with imagefilter 2016-09-26 liyuqian Fix typo 2016-09-26 egdaniel Revert of Fix bufferIndex check in VulkanWindowContext (patchset #1 id:1 of https://codereview.chromium.org/2363353003/ ) 2016-09-26 egdaniel Fix bufferIndex check in VulkanWindowContext 2016-09-26 ethannicholas Turned on SkSL->GLSL compiler GOLD_TRYBOT_URL= https://gold.skia.org/search?issue=2288033003 2016-09-26 robertphillips Minor clean up of GrAAConvexTessellator 2016-09-26 borenet Roll recipes 2016-09-26 caryclark allow conic chop to fail 2016-09-26 mtklein Turn on -Wundefined-reinterpret-cast. 2016-09-26 brianosman Tag checkerboard bitmaps as sRGB 2016-09-26 mtklein -Wcomma may be good to go now. 2016-09-26 mtklein My take on SkAlign changes. 2016-09-26 halcanary bin/coverage: a GN version of the coverage script 2016-09-26 borenet Include timestamp in nanobench JSON file name 2016-09-26 caryclark add tiger tests 2016-09-26 mtklein Typo? 2016-09-26 mtklein GN: detect is_clang, use it to switch Clang to warning blacklist. 2016-09-26 mtklein Quiet a -Wcomma warning. 2016-09-26 mtklein beziers: I missed an unsequenced moveTo() pair. 2016-09-26 robertphillips Fix some fuzzer complaints 2016-09-26 mtklein Revert "GN: detect is_clang, use it to switch Clang to warning blacklist." 2016-09-26 halcanary Documentation: fix links BUG= 650178 CQ_INCLUDE_TRYBOTS=master.tryserver.blink:linux_precise_blink_rel TBR=fmalita@google.com Review-Url: https://codereview.chromium.org/2372943002 Cr-Commit-Position: refs/heads/master@{#421107} [modify] https://crrev.com/528cb1814acc891650c6ca4801d486cee4427878/DEPS
,
Sep 27 2016
,
Sep 29 2016
ClusterFuzz has detected this issue as fixed in range 421082:421136. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6245443023667200 Fuzzer: afl_skia_pathop_fuzzer Job Type: afl_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000018 Crash State: SkOpPtT::contains AddIntersectTs OpDebug Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=420614:420693 Fixed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=421082:421136 Minimized Testcase (0.28 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95yN1ZCFnKv5w3mi5oRaDk4tZ5IuFBp3RTmXnHZ0NaCLitcUWIERwP-5Ibdf32goJ592pMpWxWrYkFomPXpVJvIEk6MWqVe66FEYmNBqXsy3QedoV7jT6weu7vz5B_vHV7pzKBifxRB6yHO8nffzBj7Cfgikw?testcase_id=6245443023667200 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||
►
Sign in to add a comment |
|||
Comment 1 by kavvaru@chromium.org
, Sep 26 2016Labels: Findit-for-crash M-55 Te-Logged
Owner: caryclark@chromium.org
Status: Assigned (was: Untriaged)