New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 765908 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Nov 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 3
Type: Bug



Sign in to add a comment

pobfuzz: GrTessellator::PathToTriangles -> path_to_polys -> tessellate integer overflow

Project Member Reported by ClusterFuzz, Sep 16 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=6196748019302400

Fuzzer: libFuzzer_paint_op_buffer_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  tessellate
  contours_to_polys
  path_to_polys
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=497456:497511

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6196748019302400

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Cc: msrchandra@chromium.org kkaluri@chromium.org
Components: Internals>GPU
Labels: M-63 Test-Predator-Wrong
Owner: senorblanco@chromium.org
Status: Assigned (was: Untriaged)
Predator and CL could not provide any possible suspects.
Using Code Search for the file, "GrTessellator.cpp" assigning to the concern owner who might be related or worked on similar file.

senorblanco@ -- Could you please look into the issue, kindly re-assign if this is not related to your changes.


Thank You.

Comment 2 by enne@chromium.org, Sep 18 2017

Cc: senorblanco@chromium.org bsalomon@chromium.org
Labels: -Pri-2 -M-63 Pri-3
Owner: ----
Status: Available (was: Assigned)
Summary: pobfuzz: GrTessellator::PathToTriangles -> path_to_polys -> tessellate integer overflow (was: Integer-overflow in tessellate)
Project Member

Comment 3 by ClusterFuzz, Oct 4 2017

Labels: Test-Predator-AutoOwner
Owner: robertph...@google.com
Status: Assigned (was: Available)
Automatically assigning owner based on suspected regression changelist https://skia.googlesource.com/skia/+/8296e752fa1803dcb8cf97d6ab10bb4f5f5f51f0 (Switch atlas clients over to using absolute texture coordinates (take 2)).

If this is incorrect, please remove the owner and apply the Test-Predator-Wrong-CLs label.

Comment 4 by mmoroz@chromium.org, Oct 24 2017

For more information, please see https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md.

The link referenced in the description is no longer valid.
Owner: robertphillips@chromium.org
Labels: -Test-Predator-AutoOwner Test-Predator-Auto-Owner
Project Member

Comment 7 by ClusterFuzz, Nov 22 2017

ClusterFuzz has detected this issue as fixed in range 518512:518527.

Detailed report: https://clusterfuzz.com/testcase?key=6196748019302400

Fuzzer: libFuzzer_paint_op_buffer_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  tessellate
  contours_to_polys
  path_to_polys
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=497456:497511
Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=518512:518527

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6196748019302400

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 8 by ClusterFuzz, Nov 22 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 6196748019302400 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment