New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 653452 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Last visit > 30 days ago
Closed: Oct 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Regression



Sign in to add a comment

Crash in starter

Project Member Reported by ClusterFuzz, Oct 6 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5376818452627456

Fuzzer: libfuzzer_skia_pathop_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  starter
  SkOpCoincidence::addOverlap
  SkOpCoincidence::findOverlaps
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=423149:423180

Minimized Testcase (0.35 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97WZ7BmRVYCTlKZa7OZD6qNqBZk1LM0ceSqcV5OB80qK83bjVtO5kQL2x05nJxH-uRRiZE0sLsT6wEHllcpwFsCAMdKbGtwreTcaCry_ZV0I1TCpic8t10mwh3N9Fz61SAUDuQ7_c0ziUx98KU-6hhv-gxDbA?testcase_id=5376818452627456

Issue manually filed by: ranjitkan

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Cc: ranjitkan@chromium.org
Components: Tools>Test>FindIt>CorrectResult
Labels: -Type-Bug Findit-for-crash M-55 Te-Logged Type-Bug-Regression
Owner: caryclark@chromium.org
Status: Assigned (was: Untriaged)
Author: Cary Clark
Project: chromium-skia
Changelist: https://chromium.googlesource.com/skia.git/+/e47ae2998c1cf944db5743a416583dd0f042b6d9
Time: Wed Oct 05 12:51:39 2016
Lines 316-319 of file SkPathOpsCommon.cpp which potentially caused crash are changed in this cl (frame #3, "HandleCoincidence").

@caryclark: Assigning to you, request you to please take a look into it. Please help us to reassign if not with respect to your change.

Thanks.!
Owner: caryclark@google.com
Status: Started (was: Assigned)
Status: Fixed (was: Started)
Project Member

Comment 6 by bugdroid1@chromium.org, Oct 7 2016

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/c243409f8f9f7cfcae4264c1b1884cbef4feef3c

commit c243409f8f9f7cfcae4264c1b1884cbef4feef3c
Author: skia-deps-roller <skia-deps-roller@chromium.org>
Date: Fri Oct 07 21:11:33 2016

Roll src/third_party/skia/ d207884bf..221a4bb55 (21 commits).

https://chromium.googlesource.com/skia.git/+log/d207884bf5d1..221a4bb55b51

$ git log d207884bf..221a4bb55 --date=short --no-merges --format='%ad %ae %s'
2016-10-07 caryclark fix fuzz busters
2016-10-07 mtklein SkRasterPipeline: 8x pipelines, attempt 2
2016-10-07 senorblanco GrTessellator: refactor Line out of Edge.
2016-10-07 bungeman Whitespace change to kick build.
2016-10-07 jvanverth Reduce geometry size for circles to help fill rate.
2016-10-07 stephana Disable svgs on nanobench when running on Valgrind
2016-10-07 mtklein Revert "SkRasterPipeline: 8x pipelines"
2016-10-06 robertphillips Disable antialiasing on interior of filled RRects that need distance vectors
2016-10-06 mtklein SkRasterPipeline: 8x pipelines
2016-10-06 fmalita Assorted Android fixes
2016-10-05 bungeman Auto re-gen for gn cmake generator.
2016-10-06 robertphillips Add distance values to interior of filled RRects
2016-10-06 fmalita Harden SkPicturePlayback::handleOp() skips
2016-10-06 egdaniel Fix Vulkan orientation during screne rotations
2016-10-06 herb Fix SkDeferredCanvas for use on android.
2016-10-06 caryclark remove sprintf
2016-10-06 mtklein Make load4 and store4 part of SkNx properly.
2016-10-06 caryclark fuzzer fix
2016-10-06 reed fix other printf warning for SkBlendMode
2016-10-06 caryclark fix mac all build
2016-10-06 xidachen Fix SkPath::arcTo when sweepAngle is tiny and radius is big

BUG= 653452 , 626164 , 640031 

CQ_INCLUDE_TRYBOTS=master.tryserver.blink:linux_precise_blink_rel
TBR=stephana@google.com

Review-Url: https://codereview.chromium.org/2405553002
Cr-Commit-Position: refs/heads/master@{#423965}

[modify] https://crrev.com/c243409f8f9f7cfcae4264c1b1884cbef4feef3c/DEPS

Project Member

Comment 7 by ClusterFuzz, Oct 8 2016

ClusterFuzz has detected this issue as fixed in range 423932:423977.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5376818452627456

Fuzzer: libfuzzer_skia_pathop_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  starter
  SkOpCoincidence::addOverlap
  SkOpCoincidence::findOverlaps
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=423149:423180
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=423932:423977

Minimized Testcase (0.35 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97WZ7BmRVYCTlKZa7OZD6qNqBZk1LM0ceSqcV5OB80qK83bjVtO5kQL2x05nJxH-uRRiZE0sLsT6wEHllcpwFsCAMdKbGtwreTcaCry_ZV0I1TCpic8t10mwh3N9Fz61SAUDuQ7_c0ziUx98KU-6hhv-gxDbA?testcase_id=5376818452627456

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 8 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment