New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 767156 link

Starred by 2 users

Issue metadata

Status: Fixed
Owner:
Closed: Oct 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Mac
Pri: 1
Type: Bug



Sign in to add a comment

Timeout in pdf_codec_jbig2_fuzzer

Project Member Reported by ClusterFuzz, Sep 20 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5210024078213120

Fuzzer: libFuzzer_pdf_codec_jbig2_fuzzer
Job Type: libfuzzer_chrome_asan_debug
Platform Id: linux

Crash Type: Timeout (exceeds 25 secs)
Crash Address: 
Crash State:
  pdf_codec_jbig2_fuzzer
  
Sanitizer: address (ASAN)

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5210024078213120

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

Note: This crash might not be reproducible with the provided testcase. That said, for the past 14 days we've been seeing this crash frequently. If you are unable to reproduce this, please try a speculative fix based on the crash stacktrace in the report. The fix can be verified by looking at the crash statistics in the report, a day after the fix is deployed. We will auto-close the bug if the crash is not seen for 14 days.
 
Cc: msrchandra@chromium.org kkaluri@chromium.org
Components: Internals>Plugins>PDF
Labels: Test-Predator-Wrong CF-NeedsTriage
Unable to provide any possible suspect using Code Search, CL and Predator.
Redo Task has been performed.
Adding CF-NeedsTriage label for further inputs.

Thank You.
Project Member

Comment 2 by ClusterFuzz, Sep 21 2017

Labels: OS-Mac

Comment 3 by mmoroz@chromium.org, Sep 30 2017

Cc: kcwu@chromium.org
Owner: thestig@chromium.org
Status: Started (was: Untriaged)

Comment 4 by mmoroz@chromium.org, Sep 30 2017

Issue 749610 has been merged into this issue.

Comment 5 by mmoroz@chromium.org, Sep 30 2017

We're going to temporarily disable this fuzz target on ClusterFuzz side, as it is wasting CPU cycles due to frequent crashing. We might not have crash stats from CF after that, but the target will stay in the repository and available for local reproducing and testing bug fixes.

https://chromium-review.googlesource.com/c/chromium/src/+/692525

Comment 6 by kcwu@chromium.org, Oct 3 2017

Just wondering maybe this issue could be added to Tasks for Fuzzathon of this year.

Sure, totally! Added 3 PDFium fuzz targets to the list.
Project Member

Comment 8 by ClusterFuzz, Oct 20 2017

Status: WontFix (was: Started)
ClusterFuzz testcase 5210024078213120 is flaky and no longer crashes, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Comment 9 by mmoroz@chromium.org, Oct 20 2017

Status: Started (was: WontFix)
Since we disabled the fuzzer, ClusterFuzz hadn't seen that crash for 14 days and decided that it was fixed. I guess it's not fixed yet, so re-opening the issue.
Cc: npm@chromium.org
For more information, please see https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md.

The link referenced in the description is no longer valid.

Comment 12 by npm@chromium.org, Oct 24 2017

Cc: -npm@chromium.org thestig@chromium.org
Owner: npm@chromium.org
I'm guessing it's not really Started, I'll take this one.
Thanks Nicolas! Once you fix this, we would need to remove "no_clusterfuzz" config from the fuzz target definition: https://cs.chromium.org/chromium/src/pdf/pdfium/fuzzers/BUILD.gn?type=cs&q=pdf_codec_jbig2_fuzzer&sq=package:chromium&l=75


Project Member

Comment 14 by bugdroid1@chromium.org, Oct 26 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/b0e44a8e1c70a59dc018b5e3bf6820fec27c219b

commit b0e44a8e1c70a59dc018b5e3bf6820fec27c219b
Author: Nicolas Pena <npm@chromium.org>
Date: Thu Oct 26 14:03:38 2017

Enable pdf_codec_jbig2_fuzzer

Bug:  767156 
Change-Id: I18955f9bde168a8877b13ecb34a8020cabd6fab6
Reviewed-on: https://chromium-review.googlesource.com/738513
Commit-Queue: dsinclair <dsinclair@chromium.org>
Reviewed-by: dsinclair <dsinclair@chromium.org>
Cr-Commit-Position: refs/heads/master@{#511812}
[modify] https://crrev.com/b0e44a8e1c70a59dc018b5e3bf6820fec27c219b/pdf/pdfium/fuzzers/BUILD.gn

Comment 15 by npm@chromium.org, Oct 26 2017

Status: Fixed (was: Started)

Sign in to add a comment