New issue
Advanced search Search tips

Issue 663280 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Nov 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Regression

Blocked on:
issue 656889

Blocking:
issue 429053



Sign in to add a comment

Crash in base::debug::DebugBreak

Project Member Reported by ClusterFuzz, Nov 8 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5563734006431744

Fuzzer: libfuzzer_gpu_fuzzer
Job Type: libfuzzer_chrome_asan_debug
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x03e900000ff5
Crash State:
  base::debug::DebugBreak
  gpu::gles2::GLES2DecoderImpl::DoCopyTexImage2D
  gpu::gles2::GLES2DecoderImpl::HandleCopyTexImage2D
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=430410:430478

Minimized Testcase (0.11 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96SLfGmWlXlQHlmpMj9rrva2-zUWjiLDuAk-S6LAP9CkWA6y7vkarO1rx69kPQ5yqqnoavI2z2TLvMJUe4oQAKm26ZtnMlQT1qfgTvrPIpqHfON7Ssgh8vp4tdSkLtKNb3ddCV34yhzlpShJKLARQ_Y8lqcQw?testcase_id=5563734006431744

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Labels: -Type-Bug Test-Predator-Wrong-CLs Type-Bug-Regression
Owner: kainino@chromium.org
Status: Assigned (was: Untriaged)
Assigning to the concern owner from the regression range,
CL --
====
https://chromium.googlesource.com/chromium/src/+log/cbbb34d866290d7b91d4c5ff4c40807a7ee7bcab..435a59e7bbcf2e5875f860317f1056d914a30610?pretty=fuller

Suspecting Commit# d74e48c456ec3334eaed3b45ca7bad5c7c681f24
Suspecting Review URL# https://codereview.chromium.org/2477673005

@kainino -- Could you please look into the issue, kindly reassign if the issue is not related to your change.
Thank You.

Comment 2 by piman@chromium.org, Nov 9 2016

Cc: zmo@chromium.org piman@chromium.org
I think it's related to my change. It's a DCHECK failure on ValidateTextureParameters. Looking into it.
Blockedon: 295792
I will get to this soon, probably tomorrow.
Blockedon: -295792
Blocking: 295792

Comment 6 by zmo@chromium.org, Nov 10 2016

Blocking: -295792 429053

Comment 7 by zmo@chromium.org, Nov 10 2016

Blockedon: 605129

Comment 8 by kbr@chromium.org, Nov 10 2016

Blockedon: -605129
Blockedon: 656889
Status: Started (was: Assigned)
Project Member

Comment 10 by bugdroid1@chromium.org, Nov 11 2016

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/4bfbee6de3147817abcb991177176df00c401046

commit 4bfbee6de3147817abcb991177176df00c401046
Author: kainino <kainino@chromium.org>
Date: Fri Nov 11 01:18:23 2016

CopyTexImage2D: don't pick invalid unsized internal formats on ES3

BUG= 663280 
CQ_INCLUDE_TRYBOTS=master.tryserver.chromium.linux:linux_optional_gpu_tests_rel;master.tryserver.chromium.mac:mac_optional_gpu_tests_rel;master.tryserver.chromium.win:win_optional_gpu_tests_rel

Review-Url: https://codereview.chromium.org/2485253005
Cr-Commit-Position: refs/heads/master@{#431437}

[modify] https://crrev.com/4bfbee6de3147817abcb991177176df00c401046/gpu/command_buffer/service/gles2_cmd_decoder.cc

Project Member

Comment 11 by ClusterFuzz, Nov 11 2016

ClusterFuzz has detected this issue as fixed in range 431432:431497.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5563734006431744

Fuzzer: libfuzzer_gpu_fuzzer
Job Type: libfuzzer_chrome_asan_debug
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x03e900000ff5
Crash State:
  base::debug::DebugBreak
  gpu::gles2::GLES2DecoderImpl::DoCopyTexImage2D
  gpu::gles2::GLES2DecoderImpl::HandleCopyTexImage2D
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=430410:430478
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=431432:431497

Minimized Testcase (0.11 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96SLfGmWlXlQHlmpMj9rrva2-zUWjiLDuAk-S6LAP9CkWA6y7vkarO1rx69kPQ5yqqnoavI2z2TLvMJUe4oQAKm26ZtnMlQT1qfgTvrPIpqHfON7Ssgh8vp4tdSkLtKNb3ddCV34yhzlpShJKLARQ_Y8lqcQw?testcase_id=5563734006431744

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 12 by ClusterFuzz, Nov 11 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Started)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 13 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment