Crash in blink::WebGLRenderingContextBase::toImageData |
||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4536150976102400 Fuzzer: inferno_twister Job Type: mac_asan_content_shell Platform Id: mac Crash Type: UNKNOWN READ Crash Address: 0x000000000020 Crash State: blink::WebGLRenderingContextBase::toImageData blink::OffscreenCanvas::convertToBlob blink::OffscreenCanvasV8Internal::convertToBlobMethodCallback Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_content_shell&range=434599:434604 Minimized Testcase (0.13 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97LO7I21TJr2diwL3-y2jUknkouSMgULsgQl20EpfZkngq5XLfA5Qpjn0eZj9QAe_uZWn1GTmbpIwgFo5diAg9Mo0jGVoozH5GXpeODmLBn_2fCkiSesv29LQ5J2E3LoPNVYFgJV6WfRoFNqcrtw13Sn87bYQ?testcase_id=4536150976102400 <script> var __v_0 = new OffscreenCanvas(1265734062, 129); var __v_1 = __v_0.getContext('webgl'); __v_0.convertToBlob() </script> Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Dec 22 2016
,
Dec 22 2016
I think the reason is that convertToBlob doesn't handle very large OffscreenCanvas at this moment.
,
Jan 5 2017
ClusterFuzz has detected this issue as fixed in range 441510:441524. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4536150976102400 Fuzzer: inferno_twister Job Type: mac_asan_content_shell Platform Id: mac Crash Type: UNKNOWN READ Crash Address: 0x000000000020 Crash State: blink::WebGLRenderingContextBase::toImageData blink::OffscreenCanvas::convertToBlob blink::OffscreenCanvasV8Internal::convertToBlobMethodCallback Sanitizer: address (ASAN) Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_content_shell&range=434599:434604 Fixed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_content_shell&range=441510:441524 Minimized Testcase (0.13 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97LO7I21TJr2diwL3-y2jUknkouSMgULsgQl20EpfZkngq5XLfA5Qpjn0eZj9QAe_uZWn1GTmbpIwgFo5diAg9Mo0jGVoozH5GXpeODmLBn_2fCkiSesv29LQ5J2E3LoPNVYFgJV6WfRoFNqcrtw13Sn87bYQ?testcase_id=4536150976102400 <script> var __v_0 = new OffscreenCanvas(1265734062, 129); var __v_1 = __v_0.getContext('webgl'); __v_0.convertToBlob() </script> See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jan 5 2017
ClusterFuzz testcase 4536150976102400 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||||
►
Sign in to add a comment |
||||
Comment 1 by sigbjo...@opera.com
, Dec 22 2016