<no crash state available> |
|||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5230964621180928 Fuzzer: sugoi_filter_fuzzer Job Type: linux_asan_filter_fuzz_stub_32bit Platform Id: linux Crash Type: UNKNOWN WRITE Crash Address: 0x00000000 Crash State: NULL Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_filter_fuzz_stub_32bit&range=386879:387080 Minimized Testcase (0.46 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95MfQZPFiABOxFiwqT31OA6Sm87Dfs8NRFrKuFEbG0JkxLHNnexjHsvuqmZli2C4j6_8e1FOu6VHzdjNoiCDdezeG2wk9Vd35y3yuRPvnZtBwj3-mC_lVOlpOkFHOMQUILztCv3PR3s2FDPinn5DJn5N_27cQ?testcase_id=5230964621180928 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Nov 11 2016
providing Findit results for internal purpose: Suspected CLs Git blame below is NOT necessarily who introduced the crash nor the owner for it. Please check the code before assigning to anyone.(No CL in the regression range changed the crashing files.) Author: erg@google.com Project: chromium Changelist: https://chromium.googlesource.com/chromium/src/+/eae9c0623d1800201739b4be146649103a45cd93 Time: Tue Jan 11 00:50:59 2011 The CL last changed line 782 of file logging.cc, which is stack frame 2. Author: erg@google.com Project: chromium Changelist: https://chromium.googlesource.com/chromium/src/+/eae9c0623d1800201739b4be146649103a45cd93 Time: Tue Jan 11 00:50:59 2011 The CL last changed line 504 of file logging.cc, which is stack frame 3. Author: sugoi@chromium.org Project: chromium Changelist: https://chromium.googlesource.com/chromium/src/+/6e8e4f83184b28130f22cc8ec184832b0d7aba2a Time: Mon Nov 18 23:35:21 2013 The CL last changed line 49 of file filter_fuzz_stub.cc, which is stack frame 4. Author: sugoi@chromium.org Project: chromium Changelist: https://chromium.googlesource.com/chromium/src/+/6e8e4f83184b28130f22cc8ec184832b0d7aba2a Time: Mon Nov 18 23:35:21 2013 The CL last changed line 66 of file filter_fuzz_stub.cc, which is stack frame 5. Author: sugoi@chromium.org Project: chromium Changelist: https://chromium.googlesource.com/chromium/src/+/6e8e4f83184b28130f22cc8ec184832b0d7aba2a Time: Mon Nov 18 23:35:21 2013 The CL last changed line 85 of file filter_fuzz_stub.cc, which is stack frame 6. Suspected Project: chromium unable to find the culprit, sugoi@ - could you please check the issue and help.
,
Nov 11 2016
Generally, when a fuzzer crashes, this is related to a code change within skia rather than within the fuzzer itself, especially since the fuzzer hasn't changed since 2013. That being said, maybe the code in skia changed in a way that would require an update to the fuzzer code. Adding mtklein@ so he can delegate this to the right person.
,
Nov 11 2016
I don't think I understand. Skia is not on this stack, is it? It looks like it's crashing in logging.
,
Nov 11 2016
Oh, ok, so something changed in the logging code, I guess? I'll try to find someone who knows about logging. Also, I don't know what this means: AddressSanitizer: soft rss limit exhausted (512Mb vs 528Mb) ASAN:DEADLYSIGNAL Is this a clusterfuzz issue? Adding mbarbella@, he might have a better understanding of this issue than me.
,
Nov 12 2016
It basically means that this is an OOM. ASan gives us an option to set an rss limit, and allocations will fail if it's exceeded.
,
Nov 16 2016
Based on offline chat with Martin I am marking the bug as P2 and someone from skia please take a look at this bug.
,
Nov 16 2016
,
Nov 16 2016
Feel free to WontFix if it doesn't seem important to handle OOM in this case. From a security perspective, there are enough ways that a compromised renderer can cause a benign browser crash that we don't really care.
,
Nov 16 2016
SGTM. We generally call malloc-or-crash routines... I'd only really be concerned here if we actively saw Skia on the stack still trying to do its thing after not crashing when it should have.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jan 22 2018
|
|||||||||
►
Sign in to add a comment |
|||||||||
Comment 1 by mummare...@chromium.org
, Nov 10 2016