New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 667991 link

Starred by 2 users

Issue metadata

Status: Verified
Owner:
Closed: Apr 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Integer-overflow in RepeatX_RepeatY_pack_filter_x

Project Member Reported by ClusterFuzz, Nov 23 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6123616648560640

Fuzzer: ifratric-browserfuzzer-v3
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  RepeatX_RepeatY_pack_filter_x
  RepeatX_RepeatY_filter_scale
  BitmapProcShaderContext::shadeSpan
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=398502:398570

Minimized Testcase (0.66 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96yZrcNkTLlLE03pUA7t3_rtjazVfr1ox1xztSxAB4VcehDR9Y7pLoHiui5Akfy5c0mNV4RBA_3JDgQhIUstT-U1aEdpWxNbBrpT68lV1G_4NLbxWhZt8esk7cHfd_1fcPHDA6bIXiHex9_XR9yEyWGpi9R6w?testcase_id=6123616648560640

Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 

Comment 1 by ajha@chromium.org, Nov 23 2016

Components: Internals>Skia
Labels: M-55
Cc: herb@chromium.org reed@chromium.org brianosman@chromium.org
Labels: Test-Predator-Wrong
Redo the task but still this issue is not fixed. could someone please take a look?
Thank you.

Comment 3 by herb@google.com, Mar 29 2017

Cc: -herb@chromium.org herb@google.com hcm@google.com
Owner: herb@google.com
I don't know what issue you are talking about. Can you please reference a bug. This is a totally new failure to me, and not part of any new code. I'm happy to look at this bug, but can you give me some more context.
Cc: manoranj...@chromium.org
Status: Assigned (was: Untriaged)
I am talking about https://clusterfuzz.com/v2/testcase-detail/6123616648560640?noredirect=1
Yesterday we re-run the test and seems that not fixed.
Thank you.

Comment 5 by herb@google.com, Mar 30 2017

This seems like a totally new bug to me. Can you point me to the CL that you thought fixed this. This in a part of code that has not been touched in a long time.
This issue is new and not fixed. sorry for the confusion. please take a look.
Thank you.
Project Member

Comment 7 by ClusterFuzz, Apr 28 2017

ClusterFuzz has detected this issue as fixed in range 467574:467606.

Detailed report: https://clusterfuzz.com/testcase?key=6123616648560640

Fuzzer: ifratric-browserfuzzer-v3
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  RepeatX_RepeatY_pack_filter_x
  RepeatX_RepeatY_filter_scale
  BitmapProcShaderContext::shadeSpan
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=398502:398570
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=467574:467606

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6123616648560640


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 8 by ClusterFuzz, Apr 28 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 6123616648560640 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment