New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 739884 link

Starred by 4 users

Issue metadata

Status: WontFix
Owner:
Closed: Jul 2017
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug

Blocking:
issue 62400



Sign in to add a comment

Out-of-memory in pdfium_xfa_fuzzer

Project Member Reported by ClusterFuzz, Jul 6 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5997073383292928

Fuzzer: libFuzzer_pdfium_xfa_fuzzer
Job Type: libfuzzer_chrome_msan
Platform Id: linux

Crash Type: Out-of-memory (exceeds 2048 MB)
Crash Address: 
Crash State:
  pdfium_xfa_fuzzer
  
Sanitizer: memory (MSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=459141:459202

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5997073383292928


Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Cc: msrchandra@chromium.org
Labels: M-61 Test-Predator-Wrong
Owner: dsinclair@chromium.org
Status: Assigned (was: Untriaged)
Predator did not provide any possible suspects.
Assigning to concern owner from CL --
https://chromium.googlesource.com/chromium/src/+log/e1b5abb6552410cef4b2de74624b24a32a3081a2..c05f3475ecaae3f033bb4ee8cfe139b8c4d0b897?pretty=fuller

@Suspecting Commit#
https://chromium.googlesource.com/chromium/src/+/034ca9381180401b9b25eac088babf7fdae847d8

@dsinclair -- Could you please look into the issue, kindly re-assign if this is not related to your changes.
Thank You.
Blocking: 62400
Labels: -Pri-1 -M-61 Pri-2
Owner: rharrison@chromium.org
Status: Started (was: Assigned)
Cc: dsinclair@chromium.org
Status: WontFix (was: Started)
This is attempting to render a page that is 224x792,792. So allocating the bitmap buffer to render is blowing the limit. This is expected behaviour.
Project Member

Comment 5 by ClusterFuzz, Jul 20 2017

Labels: Needs-Feedback
ClusterFuzz testcase 5997073383292928 is still reproducing on tip-of-tree build (trunk).

If this testcase was not reproducible locally or unworkable, ignore this notification and we will file another bug soon with hopefully a better and workable testcase.

Otherwise, if this is not intended to be fixed (e.g. this is an intentional crash), please add ClusterFuzz-Ignore label to prevent future bug filing with similar crash stacktrace.
Labels: ClusterFuzz-Ignore

Sign in to add a comment