Issue metadata
Sign in to add a comment
|
Crash in sw::Renderer::taskLoop |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=4722289303355392 Fuzzer: inferno_twister_c Job Type: windows_asan_chrome_no_sandbox Platform Id: windows Crash Type: UNKNOWN READ Crash Address: 0x2654b110 Crash State: sw::Renderer::taskLoop sw::Renderer::threadLoop sw::Renderer::threadFunction Sanitizer: address (ASAN) Recommended Security Severity: Medium Regressed: https://clusterfuzz.com/revisions?job=windows_asan_chrome_no_sandbox&range=500358:500415 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4722289303355392 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Sep 9 2017
This is a serious security regression. If you are not able to fix this quickly, please revert the change that introduced it. If this doesn't affect a release branch, or has not been properly classified for severity, please update the Security_Impact or Security_Severity labels, and remove the ReleaseBlock label. To disable this altogether, apply ReleaseBlock-NA. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Sep 9 2017
,
Sep 10 2017
,
Sep 14 2017
sugoi: Can you please take a look and reassign as appropriate? Thanks.
,
Sep 14 2017
,
Sep 14 2017
It looks like this might be caused by enabling WebGL 2 for SwiftShader: https://chromium-review.googlesource.com/653499. This is an experiment which we intend to revert before M63 banches. Alexis, could you have a look at why this crashes, and if no obvious bug is found revert WebGL 2 early to verify that this is what triggered it?
,
Sep 29 2017
sugoi: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 3 2017
,
Oct 3 2017
The following revision refers to this bug: https://swiftshader.googlesource.com/SwiftShader.git/+/42e5303dcf62a82ab26142fa755ebd01992d0c1e commit 42e5303dcf62a82ab26142fa755ebd01992d0c1e Author: Alexis Hetu <sugoi@google.com> Date: Tue Oct 03 20:04:31 2017 Fix for 3D texture sampling 3D texture sampling did not support width*height > MAX_USHORT(65535). Changed for 32 bit integer computation for that multiplication to solve this issue. Verified with 3D texture related dEQP tests. Bug b/26105892 chromium:763382 Change-Id: Ifd07278f6263d000620a0b525c07ed4fcbdcf2e7 Reviewed-on: https://swiftshader-review.googlesource.com/12988 Reviewed-by: Nicolas Capens <nicolascapens@google.com> Tested-by: Alexis Hétu <sugoi@google.com> [modify] https://crrev.com/42e5303dcf62a82ab26142fa755ebd01992d0c1e/src/Shader/SamplerCore.cpp
,
Oct 4 2017
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/5955bc576d147925fb8966ca7b91a23f7c91591e commit 5955bc576d147925fb8966ca7b91a23f7c91591e Author: Alexis Hetu <sugoi@google.com> Date: Wed Oct 04 01:03:13 2017 Roll SwiftShader bc6ce4f..9d56da2 https://swiftshader.googlesource.com/SwiftShader.git/+log/bc6ce4f..9d56da2 BUG= chromium:763382 , chromium:763384 , chromium:763435 , chromium:765094 , chromium:765791 , chromium:765939 TBR=kbr@chromium.org TEST=bots CQ_INCLUDE_TRYBOTS=master.tryserver.chromium.win:win_optional_gpu_tests_rel;master.tryserver.chromium.mac:mac_optional_gpu_tests_rel;master.tryserver.chromium.linux:linux_optional_gpu_tests_rel,linux_chromium_cfi_rel_ng;master.tryserver.chromium.android:android_optional_gpu_tests_rel Change-Id: Idd52bdc26eba54615838baf5dc65705a8a4be631 Reviewed-on: https://chromium-review.googlesource.com/699156 Commit-Queue: Alexis Hétu <sugoi@chromium.org> Reviewed-by: Alexis Hétu <sugoi@chromium.org> Cr-Commit-Position: refs/heads/master@{#506259} [modify] https://crrev.com/5955bc576d147925fb8966ca7b91a23f7c91591e/DEPS
,
Oct 4 2017
ClusterFuzz has detected this issue as fixed in range 506249:506277. Detailed report: https://clusterfuzz.com/testcase?key=4722289303355392 Fuzzer: inferno_twister_c Job Type: windows_asan_chrome_no_sandbox Platform Id: windows Crash Type: UNKNOWN READ Crash Address: 0x25e4b110 Crash State: sw::Renderer::taskLoop sw::Renderer::threadLoop sw::Renderer::threadFunction Sanitizer: address (ASAN) Recommended Security Severity: Medium Regressed: https://clusterfuzz.com/revisions?job=windows_asan_chrome_no_sandbox&range=500358:500415 Fixed: https://clusterfuzz.com/revisions?job=windows_asan_chrome_no_sandbox&range=506249:506277 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4722289303355392 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Oct 4 2017
ClusterFuzz testcase 4722289303355392 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Oct 4 2017
,
Oct 31 2017
Both regressed and fixed in M63, removing ReleaseBlock-Stable
,
Oct 31 2017
,
Jan 10 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Mar 27 2018
|
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by sheriffbot@chromium.org
, Sep 9 2017