Crash in TransformTree::OnTransformAnimated |
||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=6583480319475712 Fuzzer: dstockwell-anim-gen Job Type: windows_asan_chrome Platform Id: windows Crash Type: UNKNOWN READ Crash Address: 0x00000090 Crash State: SkMatrix44::operator== cc::TransformTree::OnTransformAnimated cc::LayerTreeImpl::SetTransformMutated Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=windows_asan_chrome&range=464127:464504 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv97nzPb8TkS0qBZqr4OUYQgUSpmoXS5WT7d233VwjKCWkAsVUX7OV9KupdIlPtd4K2Z2hnZnhThc6Z_aPawSlXLEn84O4bciXUUbOYGlbM5XPOl0QVHdXG6_P___CDKDmzk-9A3Qmi3ydwh4jh__VeBKUYSbQ95sbhromSpQtBJ28NPtJmUst7nNej3fSKnUbu1AkrkRFOF0T4xYup4NHDnAmpyAJJNr2CMlRlulxqQnCvZRLa3G6vAqkdNyJQMR_9fZbOxKpyZccRQuqIBZ5HExI49DUnQa9ky1g80MWlw27YQhFdgK3rsd-hoEOlZpdqVPBMPblqm5Iytd01NB2SoADo-stR3m_Ymm_ZVlFHyCdD-Cjmo?testcase_id=6583480319475712 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 19 2017
Predator and CL did not provide any possible suspects. Using Code Search for the file, "SkMatrix44.cpp" assigning to the concern owner. Suspecting Commit# https://skia.googlesource.com/skia.git/+/271dabaeb246ffbad88c87072432a6670751c7a8 @mtklein -- Could you please look into the issue, kindly re-assign if this is not related to your changes. Thank You.
,
Apr 19 2017
https://skia.googlesource.com/skia.git/+/271dabaeb246ffbad88c87072432a6670751c7a8 wouldn't be able to cause this.
,
Apr 19 2017
@mtklein -- Thank You for the update.
,
Apr 19 2017
Issue 713143 has been merged into this issue.
,
Apr 19 2017
This sounds like the transform tree version of the animation crash that was fixed for opacity animations by https://codereview.chromium.org/2794673002. It should be fixed when the 'real' fix for that crash (https://codereview.chromium.org/2796013003/) lands.
,
Apr 20 2017
ClusterFuzz testcase 6194233339019264 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
May 20 2017
ClusterFuzz has detected this issue as fixed in range 473029:473088. Detailed report: https://clusterfuzz.com/testcase?key=6583480319475712 Fuzzer: dstockwell-anim-gen Job Type: windows_asan_chrome Platform Id: windows Crash Type: Null-dereference READ Crash Address: 0x00000090 Crash State: SkMatrix44::operator== cc::TransformTree::OnTransformAnimated cc::LayerTreeImpl::SetTransformMutated Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=windows_asan_chrome&range=464127:464504 Fixed: https://clusterfuzz.com/revisions?job=windows_asan_chrome&range=473029:473088 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6583480319475712 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page. |
||||||
►
Sign in to add a comment |
||||||
Comment 1 by ClusterFuzz
, Apr 19 2017