Float-cast-overflow in SkRect::roundOut |
||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4698954228039680 Fuzzer: inferno_twister Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Float-cast-overflow Crash Address: Crash State: SkRect::roundOut get_unclipped_shape_dev_bounds get_shape_and_clip_bounds Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=435261:438085 Minimized Testcase (0.56 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95oZP9mUTorXymascAMYw4tVx8xmn-WUIvsUOZnX7msKZCql2rzIS3fUhuiWuBo6Ik0Jndnx16OtWIrDv9LoWwDDDbKA39LjObbsJcCft3UDCDUUzWrSZ7tzviCIdsatZzujRZCozcoB_QW_oYjRDzheFD7Ew?testcase_id=4698954228039680 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Dec 20 2016
The following revision refers to this bug: https://skia.googlesource.com/skia.git/+/c1c607e165b4306ff1fdc60139dce174019864a4 commit c1c607e165b4306ff1fdc60139dce174019864a4 Author: Brian Salomon <bsalomon@google.com> Date: Tue Dec 20 16:41:43 2016 GPU: Fix for fuzzer issue for sw-rendered paths with large bounds. BUG= 675315 Change-Id: Ida43ef878f89d0f327ef11d1c3e0df429d5760dd Reviewed-on: https://skia-review.googlesource.com/6331 Commit-Queue: Brian Salomon <bsalomon@google.com> Reviewed-by: Robert Phillips <robertphillips@google.com> [modify] https://crrev.com/c1c607e165b4306ff1fdc60139dce174019864a4/src/gpu/GrSoftwarePathRenderer.cpp
,
Dec 20 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/911fd06007472f0c79e31ba8947d8edf4661daa8 commit 911fd06007472f0c79e31ba8947d8edf4661daa8 Author: skia-deps-roller <skia-deps-roller@chromium.org> Date: Tue Dec 20 23:38:42 2016 Roll src/third_party/skia/ 86cedfc31..6ad3d2fa3 (11 commits). https://skia.googlesource.com/skia.git/+log/86cedfc31588..6ad3d2fa3858 $ git log 86cedfc31..6ad3d2fa3 --date=short --no-merges --format='%ad %ae %s' 2016-12-20 halcanary xps.gni 2016-12-20 bsalomon Rename batch->op in GrAuditTrail. 2016-12-20 brianosman Add color space xform to GrMagnifierEffect 2016-12-20 bsalomon Rename files, macros, types, and functions related to GrDrawOp testing. 2016-12-20 bsalomon Remove the last "batch tracker" from AAStrokeRectOp. 2016-12-20 brianosman Add color space xform support to GrDisplacementEffect 2016-12-20 brianosman Add color space xform bits to key for texture domain effect 2016-12-20 robertphillips Fix more Skia filter fuzzer bugs 2016-12-20 caryclark check for empty contours in sortable top 2016-12-20 bsalomon GPU: Fix for fuzzer issue for sw-rendered paths with large bounds. 2016-12-19 robertphillips Fix mapping from src to dst image space in SkAlphaThresholdFilter BUG= 675132 , 675315 , 675332 Documentation for the AutoRoller is here: https://skia.googlesource.com/buildbot/+/master/autoroll/README.md If the roll is causing failures, see: http://www.chromium.org/developers/tree-sheriffs/sheriff-details-chromium#TOC-Failures-due-to-DEPS-rolls CQ_INCLUDE_TRYBOTS=master.tryserver.blink:linux_trusty_blink_rel TBR=rmistry@google.com Review-Url: https://codereview.chromium.org/2590913005 Cr-Commit-Position: refs/heads/master@{#439928} [modify] https://crrev.com/911fd06007472f0c79e31ba8947d8edf4661daa8/DEPS
,
Dec 22 2016
ClusterFuzz has detected this issue as fixed in range 439820:440026. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4698954228039680 Fuzzer: inferno_twister Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Float-cast-overflow Crash Address: Crash State: SkRect::roundOut get_unclipped_shape_dev_bounds get_shape_and_clip_bounds Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=435261:438085 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=439820:440026 Minimized Testcase (0.56 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95oZP9mUTorXymascAMYw4tVx8xmn-WUIvsUOZnX7msKZCql2rzIS3fUhuiWuBo6Ik0Jndnx16OtWIrDv9LoWwDDDbKA39LjObbsJcCft3UDCDUUzWrSZ7tzviCIdsatZzujRZCozcoB_QW_oYjRDzheFD7Ew?testcase_id=4698954228039680 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Dec 22 2016
ClusterFuzz testcase 4698954228039680 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||
►
Sign in to add a comment |
||
Comment 1 by msrchandra@chromium.org
, Dec 19 2016Components: Internals>Skia
Labels: Test-Predator-Correct-CLs
Owner: bsalomon@chromium.org
Status: Assigned (was: Untriaged)