Crash in gpu::gles2::Shader::DoCompile |
|||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5681955191652352 Fuzzer: inferno_twister Job Type: linux_ubsan_vptr_content_shell_drt Platform Id: linux Crash Type: UNKNOWN Crash Address: 0x000000000018 Crash State: gpu::gles2::Shader::DoCompile gpu::gles2::GLES2DecoderImpl::DoGetShaderiv gpu::gles2::GLES2DecoderImpl::HandleGetShaderiv Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_content_shell_drt&range=443258:443393 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv96GMB5eUnktw-H6Fa3h9iDTWrU2EsQeqwhu5BUMfvQbZgjkvBzShy3LeUIDLr8NsMK9LS8Cl8DIoUDEfk_Mz2UPaCVtrJjgq0nT29FrG15WTNpVo_o1zTShnzqViFym4aUvDwhkWEvtCt2OwdX_y95BwaiH8cvrUfM4SRFljKf07ms5YeEWTg54-NDhJOqL2V39ikgThT1sfRoFajlpKUSKdQTE0U5722CnBQxuEkfo76IPRcgEU-dY-ik9W_utj2ptHVz_RG38SPHV_iWsKtzW-qOf90V_JsILo8RpJb_nlqgnTkqYn0mT5WRpgmv5sJEni5eP87QvifnTgnxmXlKOFby2RToSFZYQtwa0vjLasY-8B2fOp8TwNxhxWW4IFEQZFjLqe6HBNF5cvlLiaQ4xG8QJbQ?testcase_id=5681955191652352 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Mar 21 2017
Suspected CL from regression range https://chromium.googlesource.com/chromium/src/+/5b85620a5e701039630f96339a6d1b4ceb5b14f0 dongseong.hwang@, please take a look?. Thank you
,
Mar 21 2017
It's not that CL, and I don't think it's a regression I can repro the crash but only when running with --use-gl=osmesa. The crash is in osmesa, which we don't use in production (only for tests - we don't even bundle it with Chrome). osmesa hasn't changed in forever, and indeed, the crash repros at both ends of the suspected revision range. Unfortunately, I don't think it's a good idea to try to fuzz that osmesa version we have in the tree, we know it's not very stable, but realistically we can't spend much of our time fixing bugs there.
,
Mar 23 2017
,
May 18 2017
ClusterFuzz has detected this issue as fixed in range 472480:472487. Detailed report: https://clusterfuzz.com/testcase?key=5681955191652352 Fuzzer: inferno_twister Job Type: linux_ubsan_vptr_content_shell_drt Platform Id: linux Crash Type: Null-dereference Crash Address: 0x000000000018 Crash State: gpu::gles2::Shader::DoCompile gpu::gles2::GLES2DecoderImpl::DoGetShaderiv gpu::gles2::GLES2DecoderImpl::HandleGetShaderiv Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_content_shell_drt&range=443258:443393 Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_content_shell_drt&range=472480:472487 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5681955191652352 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page. |
|||
►
Sign in to add a comment |
|||
Comment 1 Deleted