New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 683308 link

Starred by 2 users

Issue metadata

Status: Verified
Owner:
not working at Google anymore
Closed: Mar 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug

Blocked on:
issue 703537



Sign in to add a comment

Undefined-shift in utf8_isNmstrt3

Project Member Reported by ClusterFuzz, Jan 20 2017

Issue description

Cc: mmoroz@chromium.org aizatsky@chromium.org
Labels: Test-Predator-Wrong M-56
Suspected CL from regression range but this CL went 6 months ago.

https://chromium.googlesource.com/chromium/src/+/8f4bcd2f2244dcde5beb4627e3e9842445948e5b

Cc-ing few developers for look into this issue. thank you.

Comment 2 by mmoroz@chromium.org, Jan 23 2017

Components: Blink>XML
Owner: nick@chromium.org
Status: Available (was: Untriaged)
Nick, as an owner of expat, would you mind taking a look?
Project Member

Comment 3 by ClusterFuzz, Mar 24 2017

ClusterFuzz has detected this issue as fixed in range 459024:459032.

Detailed report: https://clusterfuzz.com/testcase?key=4962297509576704

Fuzzer: libfuzzer_expat_xml_parse_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  utf8_isNmstrt3
  normal_scanRef
  normal_scanAtts
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=397275:397295
Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=459024:459032

Reproducer Testcase: https://clusterfuzz.com/download/AMIfv97Z04HmoNpbEVJ9aCblrhfTopI7yOppmxZpKZyWzSABDH-LnyhuOBZQENzNDp1im7fwg1v3ZbavSczVw13qVzcnxgCvV6aLAHTxSeSoRqLeh2locXo_Bz9pk5rzKNN-z86Xsp4x-7yPXL21sSEj1xkLNcXsi7jbPfUVGxgH1hfgkIYjIdNWIahYzfe05vR_t3X6y1Udch56ZIgUoj2x9RcbxDXY2YvXZrKzyGRRJJzedfZXIZzWkfhVJ4rQ2eQtQwwNO35qZS2R2WuEqmyk4NQwNEJuOi_yAwW5SS2rnap_GyPhC5LFzRedbxuMQIw8xbo2D8LNDhqpViREvbi7vJACuYnYyyikmZj44XNbS62yjhyE0qo?testcase_id=4962297509576704


See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 4 by ClusterFuzz, Mar 24 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Available)
ClusterFuzz testcase 4962297509576704 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Blockedon: 703537
Cc: qingche...@opera.com dominicc@chromium.org
qingchengl fixed this in the expat roll in r459025.

Sign in to add a comment