Timeout in boringssl_ssl_ctx_api_fuzzer |
||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5007967656345600 Fuzzer: libFuzzer_boringssl_ssl_ctx_api_fuzzer Job Type: mac_libfuzzer_chrome_asan Platform Id: mac Crash Type: Timeout (exceeds 25 secs) Crash Address: Crash State: boringssl_ssl_ctx_api_fuzzer Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=mac_libfuzzer_chrome_asan&range=447701:448014 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5007967656345600 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Jun 6 2017
This is https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=1694. The issue is this is an API fuzzer so it tries to hit contrived things that involve building unreasonably long chains and serializing them a lot. Not inherently a problem, but best not to spam everyone with false positives and slow fuzzers. :-) I landed https://boringssl.googlesource.com/boringssl/+/6da9eaeef1dd501d69cd96b891f57c22492dcd88. That hasn't rolled into Chromium yet, but it looks like that's not aggressive enough, so I've uploaded https://boringssl-review.googlesource.com/16905.
,
Jun 6 2017
The following revision refers to this bug: https://boringssl.googlesource.com/boringssl/+/b0bb83a583d2f68e30ffcacbff5141feabed7c54 commit b0bb83a583d2f68e30ffcacbff5141feabed7c54 Author: David Benjamin <davidben@google.com> Date: Tue Jun 06 20:50:55 2017 Bound ssl_ctx_api more aggressively. OpenSSL's d2i_X509 parser is amazingly slow. Only do about 10,000 of them, not 1,000,000. BUG= chromium:729419 Change-Id: I7034c3dde7d5c5681986af2ab5e516e54553d3c6 Reviewed-on: https://boringssl-review.googlesource.com/16905 Commit-Queue: David Benjamin <davidben@google.com> Commit-Queue: Adam Langley <agl@google.com> Reviewed-by: Adam Langley <agl@google.com> CQ-Verified: CQ bot account: commit-bot@chromium.org <commit-bot@chromium.org> [modify] https://crrev.com/b0bb83a583d2f68e30ffcacbff5141feabed7c54/fuzz/ssl_ctx_api.cc
,
Jun 13 2017
I believe this is fixed now. Kicked off a new task from Clusterfuzz to confirm.
,
Jun 19 2017
+kcc, is it expected that clusterfuzz take so long to rule on whether the issue's been fixed?
,
Jun 26 2017
CF seems to now believe this is not reproducible. I'm going to just close this now and assume the change fixed it.
,
Jun 27 2017
Er, I meant to close this and forgot. |
||||
►
Sign in to add a comment |
||||
Comment 1 by patricia...@chromium.org
, Jun 6 2017