New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 709786 link

Starred by 2 users

Issue metadata

Status: Verified
Owner:
Closed: Apr 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

ASSERT: mTransformFeedbackMap.find(0) != mTransformFeedbackMap.end()

Project Member Reported by ClusterFuzz, Apr 9 2017

Issue description

Cc: kbr@chromium.org zmo@chromium.org
Components: Blink>WebGL Internals>GPU>Internals
Labels: Test-Predator-Wrong M-59
Predator and regression range did not given any suspected CL. could someone please take a look?
Thank you.

Comment 2 by capn@chromium.org, Apr 12 2017

Cc: geoffl...@chromium.org jmad...@chromium.org
This is in ANGLE.

Comment 3 by zmo@chromium.org, Apr 12 2017

Cc: -geoffl...@chromium.org kainino@chromium.org
Owner: geoffl...@chromium.org
Status: Assigned (was: Untriaged)
Geoff, can you take a look?
Project Member

Comment 4 by bugdroid1@chromium.org, Apr 12 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/angle/angle/+/6e60d6bfe9f373f9dfdb9cc2621b653a27b3cbeb

commit 6e60d6bfe9f373f9dfdb9cc2621b653a27b3cbeb
Author: Geoff Lang <geofflang@chromium.org>
Date: Wed Apr 12 21:25:00 2017

Don't allow deleting the 0 transform feedback.

BUG= 709786 

Change-Id: I956cae994241a650869cee45c471074d08e79a5d
Reviewed-on: https://chromium-review.googlesource.com/475131
Reviewed-by: Corentin Wallez <cwallez@chromium.org>
Reviewed-by: Jamie Madill <jmadill@chromium.org>
Commit-Queue: Geoff Lang <geofflang@chromium.org>

[modify] https://crrev.com/6e60d6bfe9f373f9dfdb9cc2621b653a27b3cbeb/src/libANGLE/Context.cpp

Project Member

Comment 5 by bugdroid1@chromium.org, Apr 13 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/d7555a8a4f57ba001a1d6394cc47f5c10659cfc7

commit d7555a8a4f57ba001a1d6394cc47f5c10659cfc7
Author: ynovikov <ynovikov@chromium.org>
Date: Thu Apr 13 18:54:28 2017

Roll ANGLE 67f5ce4..a9042d3

https://chromium.googlesource.com/angle/angle.git/+log/67f5ce4..a9042d3

BUG= 709786 
TBR=geofflang@chromium.org, cwallez@chromium.org

TEST=bots

CQ_INCLUDE_TRYBOTS=master.tryserver.chromium.win:win_optional_gpu_tests_rel;master.tryserver.chromium.mac:mac_optional_gpu_tests_rel;master.tryserver.chromium.linux:linux_optional_gpu_tests_rel;master.tryserver.chromium.android:android_optional_gpu_tests_rel

Review-Url: https://codereview.chromium.org/2812093006
Cr-Commit-Position: refs/heads/master@{#464483}

[modify] https://crrev.com/d7555a8a4f57ba001a1d6394cc47f5c10659cfc7/DEPS

Project Member

Comment 6 by ClusterFuzz, Apr 14 2017

ClusterFuzz has detected this issue as fixed in range 464462:464505.

Detailed report: https://clusterfuzz.com/testcase?key=6504379705458688

Fuzzer: libfuzzer_gpu_angle_passthrough_fuzzer
Job Type: libfuzzer_chrome_asan_debug
Platform Id: linux

Crash Type: ASSERT
Crash Address: 
Crash State:
  mTransformFeedbackMap.find(0) != mTransformFeedbackMap.end()
  gl::Context::isTransformFeedbackGenerated
  gl::BindTransformFeedback
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan_debug&range=458072:458109
Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan_debug&range=464462:464505

Reproducer Testcase: https://clusterfuzz.com/download/AMIfv97YSkJFVr7w_ZpaXEdrUvJTDvO89pW09pj1cG2-GFjOhe-m2IFtanhVeekCV8AHLI7T6DWfmLIcGQZYLEpoBH3LXFCruamiMGuSE-hj0amGClHestvrLV4RRLkd1OWkQPHarKLRComGmJP9GocYbxADSBDbaad8MeZ5k62dvFAEXTDuxNTcTQdxucJVhljZY8Q36nbMhtKCFqRFA-RZrjgwutH5j5r55sGVC3FoSZCB9nNkoRqkLVudNnb2M9AHvFiVDjsmqovjPueyQWx6XdjP4O-Hk7FNmsMx8aWu_PH2wXWGmmZiaISblRoWLXLJ98CxgP6yD_-S6hPFHPmgmutxpE_0ttahOfta8u2c72PKlCsMNwk?testcase_id=6504379705458688


See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 7 by ClusterFuzz, Apr 14 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 6504379705458688 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment