New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 773096 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner:
Closed: Oct 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug

Blocking:
issue 793236
issue 796549



Sign in to add a comment

Out-of-memory in gpu_fuzzer

Project Member Reported by ClusterFuzz, Oct 9 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5304958139498496

Fuzzer: libFuzzer_gpu_fuzzer
Job Type: libfuzzer_chrome_msan
Platform Id: linux

Crash Type: Out-of-memory (exceeds 2048 MB)
Crash Address: 
Crash State:
  gpu_fuzzer
  
Sanitizer: memory (MSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=466873:466895

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5304958139498496

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Cc: msrchandra@chromium.org pnangunoori@chromium.org
Components: Internals>GPU
Labels: M-62 Test-Predator-Wrong CF-NeedsTriage
Unable to provide possible suspect using Predator, CL and Code Search.
Could someone please look into the issue.
Thank You.

Comment 2 by vmi...@chromium.org, Oct 13 2017

Owner: piman@chromium.org
Status: Assigned (was: Untriaged)

Comment 3 by piman@chromium.org, Oct 17 2017

Components: -Internals>GPU Internals>GPU>Internals
Labels: -Pri-1 Pri-2
There's not really much here, just one way for the client to have the service allocate arbitrary amounts of memory (which it can do otherwise), using the debug markers API. It would be pretty easy to put a limit on that, both on the string size and the stack depth. I'll whip something up.

I don't think this is security sensitive (there are many other ways by which clients can get the GPU to goo OOM, at which point it'll abort and restart), so lowering priority.
Project Member

Comment 4 by ClusterFuzz, Oct 19 2017

ClusterFuzz has detected this issue as fixed in range 509853:509885.

Detailed report: https://clusterfuzz.com/testcase?key=5304958139498496

Fuzzer: libFuzzer_gpu_fuzzer
Job Type: libfuzzer_chrome_msan
Platform Id: linux

Crash Type: Out-of-memory (exceeds 2048 MB)
Crash Address: 
Crash State:
  gpu_fuzzer
  
Sanitizer: memory (MSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=466873:466895
Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=509853:509885

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5304958139498496

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by ClusterFuzz, Oct 19 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 5304958139498496 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Status: WontFix (was: Verified)
WontFix since nothing was done to fix this.
Cc: kkaluri@chromium.org
 Issue 779348  has been merged into this issue.
Cc: piman@chromium.org
 Issue 783927  has been merged into this issue.
Blocking: 793236
 Issue 795657  has been merged into this issue.
Blocking: 796549

Sign in to add a comment