New issue
Advanced search Search tips

Issue 691244 link

Starred by 3 users

Issue metadata

Status: Verified
Owner: ----
Closed: Mar 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Undefined-shift in net::HpackVarintDecoder::Resume

Project Member Reported by ClusterFuzz, Feb 11 2017

Issue description

Cc: nyerramilli@chromium.org
Components: Internals>Network
Labels: -Type-Bug Test-Predator-Wrong-CLs M-58 Type-Bug-Regression
Owner: xunji...@chromium.org
Status: Assigned (was: Untriaged)
Findit did not find any culprit results, using codesearch

seeing some recent changes to 'http2_hpack_decoder.cc' https://chromium.googlesource.com/chromium/src/+/ec84e4ea604deb4d6cca4b72ce6f97babf99878b

xunjieli@, could you please check the issue and help.
FWIW, it's a new fuzzer, not a regression in existing one.
 Issue #691214  might be the same.
Components: -Internals>Network Internals>Network>HTTP2
Labels: -Type-Bug-Regression Type-Bug
Owner: ----
Status: Available (was: Assigned)
Project Member

Comment 4 by ClusterFuzz, Mar 4 2017

ClusterFuzz has detected this issue as fixed in range 454694:454733.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5967113060876288

Fuzzer: libfuzzer_net_spdy_session_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  net::HpackVarintDecoder::Resume
  bool net::HpackStringDecoder::StartDecodingLength<net::ValueDecoderListener>
  net::DecodeStatus net::HpackStringDecoder::Resume<net::ValueDecoderListener>
  
Sanitizer: undefined (UBSAN)

Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=449628:449664
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=454694:454733

Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv95cTDZ95t1AC22byQOMRxDBVMtEXBTIxf4L9qfEMMFgPRHWSjYSHG0EL0vULiXBzedUhbWNvBHSVE23i4CB6U63F18cIa2vV87Qyo0ywbkZJLZYPP70ZiOCSazf4bf8R89B_394w_yvyNrbDvGTq-aTZ3C6elp1uG3yMb231_cJIn0ubg38HR3F_lzFjci9EJJQymDHMxo7JWHBO0WHTzTQ769JU5xo-CVXga4PYPCsQdw6C3AYWEyA3fNA7mtOfSNAn2U_NTs1mxK7y27SNbyUaBbP_ZtU6_JcTvr9HlNJZU-XikRVcbgRXVG-U6dVI4m9uxSf84mNGdYsZE5IY9RmQ0TtcLgwJ3VEbYoyST8cYW5pYP123onet5CgFAdF0bMng6NbAjxmzcdYNZSHIPW_Ip00NA?testcase_id=5967113060876288


See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by ClusterFuzz, Mar 4 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Available)
ClusterFuzz testcase 5967113060876288 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment