Null-dereference READ in rewind |
|||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5039277800161280 Fuzzer: inferno_layout_test_unmodified Job Type: mac_asan_chrome Platform Id: mac Crash Type: Null-dereference READ Crash Address: 0x000000000028 Crash State: rewind merge_edges_below merge_collinear_edges Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=477544:477573 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5039277800161280 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jun 12 2017
The following revision refers to this bug: https://skia.googlesource.com/skia/+/e3a0be73a61147379ab0ce33a0e773c072c47908 commit e3a0be73a61147379ab0ce33a0e773c072c47908 Author: Stephen White <senorblanco@chromium.org> Date: Mon Jun 12 17:44:23 2017 GrTessellator: fix two NaN issues. If a point in the path rounds to +inf/-inf, the intersection code can produce NaN, which is unsortable. Fix: ignore non-finite intersections. Quadratic interpolation can sometimes produce NaN, which will never satisfy the flatness criterion. Abort if any of the interpolated points are non-finite. Bug:732023 Change-Id: If5881796e589c75b8f74459f42d00918619713a2 Reviewed-on: https://skia-review.googlesource.com/19467 Reviewed-by: Brian Salomon <bsalomon@google.com> Commit-Queue: Stephen White <senorblanco@chromium.org> [modify] https://crrev.com/e3a0be73a61147379ab0ce33a0e773c072c47908/tests/TessellatingPathRendererTests.cpp [modify] https://crrev.com/e3a0be73a61147379ab0ce33a0e773c072c47908/src/gpu/GrTessellator.cpp
,
Jun 12 2017
,
Jun 16 2017
,
Jun 20 2017
ClusterFuzz has detected this issue as fixed in range 478717:478791. Detailed report: https://clusterfuzz.com/testcase?key=5039277800161280 Fuzzer: inferno_layout_test_unmodified Job Type: mac_asan_chrome Platform Id: mac Crash Type: Null-dereference READ Crash Address: 0x000000000028 Crash State: rewind merge_edges_below merge_collinear_edges Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=477544:477573 Fixed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=478717:478791 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5039277800161280 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jun 20 2017
ClusterFuzz has detected this issue as fixed in range 478717:478791. Detailed report: https://clusterfuzz.com/testcase?key=5039277800161280 Fuzzer: inferno_layout_test_unmodified Job Type: mac_asan_chrome Platform Id: mac Crash Type: Null-dereference READ Crash Address: 0x000000000028 Crash State: rewind merge_edges_below merge_collinear_edges Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=477544:477573 Fixed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=478717:478791 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5039277800161280 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page. |
|||
►
Sign in to add a comment |
|||
Comment 1 by msrchandra@chromium.org
, Jun 12 2017Components: Internals>GPU>Rasterization
Labels: M-61 Test-Predator-Correct-CLs
Owner: senorblanco@chromium.org
Status: Assigned (was: Untriaged)