New issue
Advanced search Search tips

Issue 659417 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Dec 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: ----
Type: Bug

Blocking:
issue 62400



Sign in to add a comment

code <= code_next

Project Member Reported by ClusterFuzz, Oct 26 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4547851414929408

Fuzzer: libfuzzer_pdf_codec_gif_fuzzer
Job Type: libfuzzer_chrome_asan_debug
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  code <= code_next
  CGifLZWDecoder::DecodeString
  CGifLZWDecoder::Decode
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=400732:400874

Minimized Testcase (0.06 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96NlSmE4pekCQevTCLyDB5tn5VpcVwdQUTIbgothG_UEfY46YHUvV-RzyTf8gWa2sYNBp6s4sBHkvcEjdkVNF-PMPizWpMN9wJhrB6LIduisRIJStHEJmHBYmSrBdrZJ3AXI2oqy51rOV2MknpwBDJRmrEExw?testcase_id=4547851414929408

Additional requirements: Requires Gestures

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 

Comment 1 by aarya@google.com, Oct 26 2016

Labels: -Restrict-View-SecurityTeam Restrict-View-EditIssue Type-Bug
These were incorrectly filed as security bugs, removing security tags.

Comment 2 by aarya@google.com, Oct 26 2016

Labels: -Security_Severity-High -Security_Impact-Stable
Labels: Test-Predator-Correct
Owner: dsinclair@chromium.org
Status: Assigned (was: Untriaged)
Suspected CLs:
======================
Git blame below is NOT necessarily who introduced the crash nor the owner for it. Please check the code before assigning to anyone.(No CL in the regression range changed the crashing files.)

Author: Dan Sinclair
Project: chromium-pdfium
Changelist: https://pdfium.googlesource.com/pdfium.git/+/764ec513eecbebd12781bcc96ce81ed5e736ee92
Time: Mon Mar 14 13:35:12 2016 -0400
The CL last changed line 62 of file fx_gif.cpp, which is stack frame 4.

Author: Dan Sinclair
Project: chromium-pdfium
Changelist: https://pdfium.googlesource.com/pdfium.git/+/764ec513eecbebd12781bcc96ce81ed5e736ee92
Time: Mon Mar 14 13:35:12 2016 -0400
The CL last changed line 143 of file fx_gif.cpp, which is stack frame 5.

Author: Dan Sinclair
Project: chromium-pdfium
Changelist: https://pdfium.googlesource.com/pdfium.git/+/764ec513eecbebd12781bcc96ce81ed5e736ee92
Time: Mon Mar 14 13:35:12 2016 -0400
The CL last changed line 925 of file fx_gif.cpp, which is stack frame 6.
======================

Suspected Project: chromium

dsinclair@ : Could you please take a look into this if its related to your change, feel free to un-assign from it and help us assigning to an appropriatre owner for the same if its not related to your change.
Blocking: 62400
Components: Internals>Plugins>PDF
Project Member

Comment 5 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 6 by npm@chromium.org, Dec 1 2016

Cc: dsinclair@chromium.org
Owner: npm@chromium.org

Comment 7 by npm@chromium.org, Dec 1 2016

 Issue 659281  has been merged into this issue.

Comment 8 by npm@chromium.org, Dec 1 2016

Status: Fixed (was: Assigned)
https://codereview.chromium.org/2542673004/
Project Member

Comment 9 by bugdroid1@chromium.org, Dec 1 2016

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/5c6594ed13ddecc2f5dcfcbbe2f0d4400b1b173f

commit 5c6594ed13ddecc2f5dcfcbbe2f0d4400b1b173f
Author: pdfium-deps-roller <pdfium-deps-roller@chromium.org>
Date: Thu Dec 01 20:03:18 2016

Roll src/third_party/pdfium/ 02759102c..9be9c3486 (1 commit).

https://pdfium.googlesource.com/pdfium.git/+log/02759102cf99..9be9c3486688

$ git log 02759102c..9be9c3486 --date=short --no-merges --format='%ad %ae %s'
2016-12-01 npm Improve early return in CGifLZWDecoder::Decode

BUG= 659417 

Documentation for the AutoRoller is here:
https://skia.googlesource.com/buildbot/+/master/autoroll/README.md

If the roll is causing failures, see:
http://www.chromium.org/developers/tree-sheriffs/sheriff-details-chromium#TOC-Failures-due-to-DEPS-rolls

TBR=dsinclair@chromium.org

Review-Url: https://codereview.chromium.org/2544863002
Cr-Commit-Position: refs/heads/master@{#435682}

[modify] https://crrev.com/5c6594ed13ddecc2f5dcfcbbe2f0d4400b1b173f/DEPS

Sign in to add a comment