start_pos >= 0 |
||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4790989131874304 Fuzzer: libfuzzer_pdf_codec_fax_fuzzer Job Type: libfuzzer_chrome_asan_debug Platform Id: linux Crash Type: ASSERT Crash Address: Crash State: start_pos >= 0 libpthread.so.0 FindBit Sanitizer: address (ASAN) Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=455091:455226 Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97EnEcRdbVojLHP9Ksacxpl61gkdXKatq1gCrI4EQkWaD1HhOZdyCG8c-zvQ89jgzs6yB4YiNoOPNCwuuTVTa_kBjFnocWsWT1FuRyqHo5E68gL00KVqXp-XbjMrSWSHzkPQSqPkn9pSC_GUMLUVg5VS9gcqHTxgSDu6c4nGu7NHSfK-1grRiezOVjPDTCJDW_czVxS6O_08d2Q63kZm_J_KZO6VaSKQ403ylkqjoZYHpTTozoNv7ixJDGFvHwm03fSaroOLS0YwXpY_2q-S594bUUOqDW3A_I_db6sIAwZVQVUXT0X8O3RUDS0CDYG0QMpYL3hdS34qkM8W4xxV60Te3zP51ZgZ8gFghYewCzUdrswB7I?testcase_id=4790989131874304 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Mar 8 2017
I don't have time to help recently, reassign.
,
Mar 8 2017
npm@ can you take a look?
,
Mar 13 2017
The following revision refers to this bug: https://pdfium.googlesource.com/pdfium/+/8ba662443cd7bc3bdad1699cf014c2ecb432e453 commit 8ba662443cd7bc3bdad1699cf014c2ecb432e453 Author: Nicolas Pena <npm@chromium.org> Date: Mon Mar 13 18:48:08 2017 Check run lengths in FaxG4GetRow The spec says a1 is to the right of a0, a2 to the right of a1. I think that means that the run lengths have to be positive, but that certainly means that they cannot be negative. BUG= chromium:699340 Change-Id: Ic07a272e63610f7a66c5073179cdb2768f80e2b8 Reviewed-on: https://pdfium-review.googlesource.com/2963 Reviewed-by: Tom Sepez <tsepez@chromium.org> Reviewed-by: dsinclair <dsinclair@chromium.org> Commit-Queue: Nicolás Peña <npm@chromium.org> [modify] https://crrev.com/8ba662443cd7bc3bdad1699cf014c2ecb432e453/core/fxcodec/codec/fx_codec_fax.cpp
,
Mar 13 2017
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/ead4ab4ffb0784d727e827d901d708b38a1cefe1 commit ead4ab4ffb0784d727e827d901d708b38a1cefe1 Author: pdfium-deps-roller <pdfium-deps-roller@chromium.org> Date: Mon Mar 13 23:26:31 2017 Roll src/third_party/pdfium/ 9818dc150..4ca5ba4de (5 commits) https://pdfium.googlesource.com/pdfium.git/+log/9818dc150132..4ca5ba4dec65 $ git log 9818dc150..4ca5ba4de --date=short --no-merges --format='%ad %ae %s' 2017-03-13 npm Fix boundary value negation in bmp_read_header 2017-03-13 dsinclair Add utf-8 flag to win build. 2017-03-10 thestig Make most PDFium code pass Clang plugin's auto raw check. 2017-03-13 npm Fix some nits in fx_codec_fax 2017-03-13 npm Check run lengths in FaxG4GetRow Created with: roll-dep src/third_party/pdfium BUG= 628559 , 699340 Documentation for the AutoRoller is here: https://skia.googlesource.com/buildbot/+/master/autoroll/README.md If the roll is causing failures, see: http://www.chromium.org/developers/tree-sheriffs/sheriff-details-chromium#TOC-Failures-due-to-DEPS-rolls TBR=dsinclair@chromium.org Review-Url: https://codereview.chromium.org/2749553004 Cr-Commit-Position: refs/heads/master@{#456539} [modify] https://crrev.com/ead4ab4ffb0784d727e827d901d708b38a1cefe1/DEPS
,
Mar 14 2017
ClusterFuzz has detected this issue as fixed in range 456526:456561. Detailed report: https://clusterfuzz.com/testcase?key=4790989131874304 Fuzzer: libfuzzer_pdf_codec_fax_fuzzer Job Type: libfuzzer_chrome_asan_debug Platform Id: linux Crash Type: ASSERT Crash Address: Crash State: start_pos >= 0 FindBit FaxG4FindB1B2 Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan_debug&range=455091:455226 Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan_debug&range=456526:456561 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv94KM6vZ3K0-jfbALTju-i4hHim69g8EAvAYyAHULAYaYoKpsX3eFG16AjE17DXGZGm5eaEpPK7FFTNso-bJRgJEDndrND0MtFaHGa_f1_WPIgOar7ct3A1Ra80ph-HNGDx05ajAj3HhQlbNB8L6ovPI-yuB7IgF9rJd0aZ37sIncY4kZLo0NcnVFv7Hhv9uSHlmUkCqabdX0sVl_viBfQvcvRof6yi4J0AYj4TyUs59PBZoTADO8TyDPiIil3Uiyo0ZILWe7RKCX7zJxzph0i6YBaTgl-80NquTVE6GSDvVBnKlFEnMg6ZkGHO4PJkKBKcgQELP91RB4cv5j1_GvNkpXZ9ztobcxFHFaVQu8f94ReoVJvw?testcase_id=4790989131874304 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Mar 14 2017
ClusterFuzz testcase 4790989131874304 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||||
►
Sign in to add a comment |
||||
Comment 1 by durga.behera@chromium.org
, Mar 8 2017Labels: 59 Test-Predator-Correct-CLs
Owner: kcwu@chromium.org
Status: Assigned (was: Untriaged)