New issue
Advanced search Search tips

Issue 663102 link

Starred by 1 user

Issue metadata

Status: Verified
Owner: ----
Closed: Nov 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug-Regression



Sign in to add a comment

Crash in SkAAClipBlitter::blitAntiH

Project Member Reported by ClusterFuzz, Nov 7 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4748345353699328

Fuzzer: ifratric-browserfuzzer-v3
Job Type: linux_asan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  SkAAClipBlitter::blitAntiH
  RunBasedAdditiveBlitter::flush
  SkScan::AAAFillPath
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=430188:430192

Minimized Testcase (0.32 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97flBFRTkwSM7dM4-OVixJRbY926idx_JC9QJa9LxcgS5TjPZroIpR7wFU5Dx-_Z3FiMhspZ210TtXGI7nVCDHa2QOCYlrjWrrpik74DsEwYM10ziNuXL38X5K-WOQfy22dtGjq8lmySdzVifU1uZe_P6t2Tw?testcase_id=4748345353699328

Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: nyerramilli@chromium.org
Components: Internals>Skia
Labels: -Pri-1 -Type-Bug Test-Predator-Wrong-CLs M-56 Pri-2 Type-Bug-Regression
providing Findit results for internal purpose:
Suspected CLs	Git blame below is NOT necessarily who introduced the crash nor the owner for it. Please check the code before assigning to anyone.(No CL in the regression range changed the crashing files.)

Author: reed@google.com
Project: chromium-skia
Changelist: https://skia.googlesource.com/skia.git/+/e36707a4a82a4dea7d480d969220f3ed223305dc
Time: Tue Oct 04 21:38:55 2011 +0000
The CL last changed line 894 of file SkAAClip.cpp, which is stack frame 0.

Author: reed@google.com
Project: chromium-skia
Changelist: https://skia.googlesource.com/skia.git/+/e36707a4a82a4dea7d480d969220f3ed223305dc
Time: Tue Oct 04 21:38:55 2011 +0000
The CL last changed line 2004 of file SkAAClip.cpp, which is stack frame 1.

Author: liyuqian
Project: chromium-skia
Changelist: https://skia.googlesource.com/skia.git/+/38911a7cb53474575e1cd1cb545902b50ee00889
Time: Tue Oct 04 11:23:22 2016 -0700
The CL last changed line 350 of file SkScan_AAAPath.cpp, which is stack frame 2.

Author: liyuqian
Project: chromium-skia
Changelist: https://skia.googlesource.com/skia.git/+/38911a7cb53474575e1cd1cb545902b50ee00889
Time: Tue Oct 04 11:23:22 2016 -0700
The CL last changed line 399 of file SkScan_AAAPath.cpp, which is stack frame 3.

Author: liyuqian
Project: chromium-skia
Changelist: https://skia.googlesource.com/skia.git/+/38911a7cb53474575e1cd1cb545902b50ee00889
Time: Tue Oct 04 11:23:22 2016 -0700
The CL last changed line 1325 of file SkScan_AAAPath.cpp, which is stack frame 4.

Author: liyuqian
Project: chromium-skia
Changelist: https://skia.googlesource.com/skia.git/+/6a7287c14ba39784d66bb299a1340c0d7ca7b683
Time: Fri Oct 21 09:07:41 2016 -0700
The CL last changed line 1348 of file SkScan_AAAPath.cpp, which is stack frame 5.

Author: liyuqian
Project: chromium-skia
Changelist: https://skia.googlesource.com/skia.git/+/38911a7cb53474575e1cd1cb545902b50ee00889
Time: Tue Oct 04 11:23:22 2016 -0700
The CL last changed line 754 of file SkScan_AntiPath.cpp, which is stack frame 6.

Suspected Project: chromium-skia
Suspected Component: Internals>Skia

requesting skia team to check the issue.
Project Member

Comment 2 by ClusterFuzz, Nov 8 2016

ClusterFuzz has detected this issue as fixed in range 430262:430287.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4748345353699328

Fuzzer: ifratric-browserfuzzer-v3
Job Type: linux_asan_chrome_mp
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  SkAAClipBlitter::blitAntiH
  RunBasedAdditiveBlitter::flush
  SkScan::AAAFillPath
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=430188:430192
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=430262:430287

Minimized Testcase (0.32 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97flBFRTkwSM7dM4-OVixJRbY926idx_JC9QJa9LxcgS5TjPZroIpR7wFU5Dx-_Z3FiMhspZ210TtXGI7nVCDHa2QOCYlrjWrrpik74DsEwYM10ziNuXL38X5K-WOQfy22dtGjq8lmySdzVifU1uZe_P6t2Tw?testcase_id=4748345353699328

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 3 by ClusterFuzz, Nov 8 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Untriaged)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 4 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment