New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 789812 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Dec 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Windows , Chrome , Mac , Fuchsia
Pri: 1
Type: Bug-Security



Sign in to add a comment

Use-of-uninitialized-value in sse41::blit_row_s32a_opaque

Project Member Reported by ClusterFuzz, Nov 30 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5449983540330496

Fuzzer: ifratric-browserfuzzer-v3
Job Type: linux_msan_chrome
Platform Id: linux

Crash Type: Use-of-uninitialized-value
Crash Address: 
Crash State:
  sse41::blit_row_s32a_opaque
  SkARGB32_Shader_Blitter::blitRect
  SkScan::FillIRect
  
Sanitizer: memory (MSAN)

Recommended Security Severity: Medium

Regressed: https://clusterfuzz.com/revisions?job=linux_msan_chrome&range=519805:519843

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5449983540330496

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Nov 30 2017

Cc: herb@google.com bsheedy@google.com brucedaw...@chromium.org
Labels: Test-Predator-Auto-CC
Automatically adding ccs based on suspected regression changelists:

Crash if TerminateProcess returns by brucedawson@chromium.org - https://chromium.googlesource.com/chromium/src/+/33ce2ffff68d58899b6e5b598e8b1c1a7eccfd91

Make Skia compatible with Android NDK r16 by bsheedy@google.com - https://skia.googlesource.com/skia/+/592c225b03ca677a1217eabdbc38eede6afcdb14

Turn on new image blur for chrome. by herb@google.com - https://chromium.googlesource.com/chromium/src/+/270b4e2bc7cf1949e30a40db72cde6be91f68041

If this is incorrect, please apply the Test-Predator-Wrong-CLs label.
Owner: herb@google.com
Status: Assigned (was: Untriaged)
It's almost certainly this change:

Turn on new image blur for chrome. by herb@google.com - https://chromium.googlesource.com/chromium/src/+/270b4e2bc7cf1949e30a40db72cde6be91f68041

Project Member

Comment 3 by sheriffbot@chromium.org, Nov 30 2017

Labels: M-64
Project Member

Comment 4 by sheriffbot@chromium.org, Nov 30 2017

Labels: ReleaseBlock-Stable
This is a serious security regression. If you are not able to fix this quickly, please revert the change that introduced it.

If this doesn't affect a release branch, or has not been properly classified for severity, please update the Security_Impact or Security_Severity labels, and remove the ReleaseBlock label. To disable this altogether, apply ReleaseBlock-NA.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 5 by sheriffbot@chromium.org, Nov 30 2017

Labels: Pri-1

Comment 6 by herb@google.com, Nov 30 2017

Cc: fmalita@chromium.org
Let's just revery my change.

Comment 7 by palmer@chromium.org, Nov 30 2017

Cc: hcm@chromium.org
Components: Internals>Skia
Labels: OS-Android OS-Chrome OS-Fuchsia OS-Mac OS-Windows
Project Member

Comment 8 by bugdroid1@chromium.org, Nov 30 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/d1cfefaa74228627c0c62ee4f6a57b65b388d523

commit d1cfefaa74228627c0c62ee4f6a57b65b388d523
Author: Herb Derby <herb@chromium.org>
Date: Thu Nov 30 19:04:44 2017

Revert "Turn on new image blur for chrome."

This reverts commit 270b4e2bc7cf1949e30a40db72cde6be91f68041.

Reason for revert: causes msan regression in fuzzer

BUG= 789812 

TBR=danakj@chromium.org

Original change's description:
> Turn on new image blur for chrome.
>
> BUG= 472742 
>
> Cq-Include-Trybots: master.tryserver.chromium.android:android_optional_gpu_tests_rel
> Change-Id: Iddaaf37132faf2698c09ae0851c741fb78d97656
> Reviewed-on: https://chromium-review.googlesource.com/791010
> Reviewed-by: danakj <danakj@chromium.org>
> Reviewed-by: Florin Malita <fmalita@chromium.org>
> Commit-Queue: Herb Derby <herb@chromium.org>
> Cr-Commit-Position: refs/heads/master@{#519831}

TBR=danakj@chromium.org,fmalita@chromium.org,herb@chromium.org

# Not skipping CQ checks because original CL landed > 1 day ago.

Bug:  472742 
Change-Id: Ia7a31e8ec46679b69e2bad02896921da45dc279a
Cq-Include-Trybots: master.tryserver.chromium.android:android_optional_gpu_tests_rel
Reviewed-on: https://chromium-review.googlesource.com/801150
Commit-Queue: Herb Derby <herb@chromium.org>
Reviewed-by: Florin Malita <fmalita@chromium.org>
Cr-Commit-Position: refs/heads/master@{#520628}
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/components/viz/test/data/blur_filter_with_clip_sw.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/skia/config/SkUserConfig.h
[add] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/compositing/overflow/mask-with-filter-expected.png
[delete] https://crrev.com/8a0aea1a5361dbc35f98bdfafcb22beb249072bb/third_party/WebKit/LayoutTests/css3/filters/blur-filter-page-scroll-self-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/css3/filters/crash-filter-change-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/css3/filters/effect-blur-expected.png
[add] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/css3/filters/filter-change-repaint-expected.png
[delete] https://crrev.com/8a0aea1a5361dbc35f98bdfafcb22beb249072bb/third_party/WebKit/LayoutTests/css3/filters/filter-repaint-blur-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/css3/filters/filter-repaint-child-layers-expected.png
[delete] https://crrev.com/8a0aea1a5361dbc35f98bdfafcb22beb249072bb/third_party/WebKit/LayoutTests/css3/filters/filter-repaint-expected.png
[delete] https://crrev.com/8a0aea1a5361dbc35f98bdfafcb22beb249072bb/third_party/WebKit/LayoutTests/css3/filters/filter-repaint-shadow-expected.png
[delete] https://crrev.com/8a0aea1a5361dbc35f98bdfafcb22beb249072bb/third_party/WebKit/LayoutTests/css3/filters/filtered-inline-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/css3/filters/regions-expanding-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/images/color-profile-mask-image-svg-expected.png
[delete] https://crrev.com/8a0aea1a5361dbc35f98bdfafcb22beb249072bb/third_party/WebKit/LayoutTests/paint/invalidation/svg/filter-child-repaint-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/paint/invalidation/svg/invalidate-on-child-layout-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/paint/invalidation/svg/resource-invalidate-on-target-update-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/linux/compositing/masks/mask-with-added-filters-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/linux/fast/canvas/canvas-composite-video-shadow-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/linux/fast/canvas/canvas-incremental-repaint-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/linux/fast/canvas/canvas-shadow-source-in-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/linux/images/color-profile-image-filter-all-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/linux/paint/filters/clip-filter-overflow-clip-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/linux/paint/invalidation/svg/filter-width-update-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/linux/svg/W3C-SVG-1.1/filters-example-01-b-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/linux/svg/W3C-SVG-1.1/filters-gauss-01-b-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/linux/svg/batik/text/smallFonts-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/linux/svg/batik/text/textEffect-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/linux/svg/batik/text/textEffect3-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/linux/svg/batik/text/textFeatures-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/linux/svg/batik/text/textProperties-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/linux/svg/custom/image-with-transform-clip-filter-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/linux/svg/custom/recursive-filter-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/linux/svg/custom/text-filter-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/linux/svg/filters/filter-on-filter-for-text-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/linux/virtual/display_list_2d_canvas/fast/canvas/canvas-composite-video-shadow-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/linux/virtual/display_list_2d_canvas/fast/canvas/canvas-incremental-repaint-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/linux/virtual/display_list_2d_canvas/fast/canvas/canvas-shadow-source-in-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/linux/virtual/exotic-color-space/images/color-profile-image-filter-all-expected.png
[delete] https://crrev.com/8a0aea1a5361dbc35f98bdfafcb22beb249072bb/third_party/WebKit/LayoutTests/platform/linux/virtual/spv175/compositing/overflow/mask-with-filter-expected.png
[delete] https://crrev.com/8a0aea1a5361dbc35f98bdfafcb22beb249072bb/third_party/WebKit/LayoutTests/platform/linux/virtual/spv175/paint/filters/clip-filter-overflow-clip-expected.png
[delete] https://crrev.com/8a0aea1a5361dbc35f98bdfafcb22beb249072bb/third_party/WebKit/LayoutTests/platform/linux/virtual/spv175/paint/invalidation/svg/filter-width-update-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/compositing/masks/mask-with-added-filters-expected.png
[delete] https://crrev.com/8a0aea1a5361dbc35f98bdfafcb22beb249072bb/third_party/WebKit/LayoutTests/platform/mac/compositing/overflow/mask-with-filter-expected.png
[add] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/css3/filters/blur-filter-page-scroll-self-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/css3/filters/effect-brightness-clamping-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/css3/filters/effect-combined-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/css3/filters/effect-drop-shadow-expected.png
[delete] https://crrev.com/8a0aea1a5361dbc35f98bdfafcb22beb249072bb/third_party/WebKit/LayoutTests/platform/mac/css3/filters/filter-change-repaint-expected.png
[add] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/css3/filters/filter-repaint-blur-expected.png
[add] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/css3/filters/filter-repaint-expected.png
[add] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/css3/filters/filter-repaint-shadow-expected.png
[add] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/css3/filters/filtered-inline-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/fast/canvas/canvas-composite-video-shadow-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/fast/canvas/canvas-incremental-repaint-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/fast/canvas/canvas-shadow-source-in-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/images/color-profile-filter-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/images/color-profile-image-filter-all-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/paint/filters/clip-filter-overflow-clip-expected.png
[add] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/paint/invalidation/svg/filter-child-repaint-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/paint/invalidation/svg/filter-width-update-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/svg/W3C-SVG-1.1/filters-example-01-b-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/svg/W3C-SVG-1.1/filters-gauss-01-b-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/svg/batik/text/smallFonts-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/svg/batik/text/textEffect-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/svg/batik/text/textEffect3-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/svg/batik/text/textFeatures-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/svg/batik/text/textProperties-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/svg/custom/image-with-transform-clip-filter-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/svg/custom/recursive-filter-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/svg/custom/text-filter-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/svg/filters/filter-on-filter-for-text-expected.png
[add] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/virtual/display_list_2d_canvas/fast/canvas/canvas-composite-video-shadow-expected.png
[add] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/virtual/display_list_2d_canvas/fast/canvas/canvas-incremental-repaint-expected.png
[add] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/virtual/display_list_2d_canvas/fast/canvas/canvas-shadow-source-in-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/virtual/exotic-color-space/images/color-profile-filter-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/mac/virtual/exotic-color-space/images/color-profile-image-filter-all-expected.png
[delete] https://crrev.com/8a0aea1a5361dbc35f98bdfafcb22beb249072bb/third_party/WebKit/LayoutTests/platform/mac/virtual/exotic-color-space/images/color-profile-mask-image-svg-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/compositing/masks/mask-with-added-filters-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/compositing/overflow/mask-with-filter-expected.png
[add] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/css3/filters/blur-filter-page-scroll-self-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/css3/filters/effect-brightness-clamping-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/css3/filters/effect-combined-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/css3/filters/effect-drop-shadow-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/css3/filters/filter-change-repaint-expected.png
[add] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/css3/filters/filter-repaint-blur-expected.png
[add] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/css3/filters/filter-repaint-expected.png
[add] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/css3/filters/filter-repaint-shadow-expected.png
[add] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/css3/filters/filtered-inline-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/fast/canvas/canvas-composite-video-shadow-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/fast/canvas/canvas-incremental-repaint-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/fast/canvas/canvas-shadow-source-in-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/images/color-profile-filter-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/images/color-profile-image-filter-all-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/paint/filters/clip-filter-overflow-clip-expected.png
[add] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/paint/invalidation/svg/filter-child-repaint-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/paint/invalidation/svg/filter-width-update-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/svg/W3C-SVG-1.1/filters-example-01-b-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/svg/W3C-SVG-1.1/filters-gauss-01-b-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/svg/batik/text/smallFonts-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/svg/batik/text/textEffect-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/svg/batik/text/textEffect3-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/svg/batik/text/textFeatures-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/svg/batik/text/textProperties-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/svg/custom/image-with-transform-clip-filter-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/svg/custom/recursive-filter-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/svg/custom/text-filter-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/svg/filters/filter-on-filter-for-text-expected.png
[add] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/virtual/display_list_2d_canvas/fast/canvas/canvas-composite-video-shadow-expected.png
[add] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/virtual/display_list_2d_canvas/fast/canvas/canvas-incremental-repaint-expected.png
[add] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/virtual/display_list_2d_canvas/fast/canvas/canvas-shadow-source-in-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/virtual/exotic-color-space/images/color-profile-filter-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/virtual/exotic-color-space/images/color-profile-image-filter-all-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/platform/win/virtual/exotic-color-space/images/color-profile-mask-image-svg-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/css/path-gradient-stroke-shadow-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/css/rect-gradient-stroke-shadow-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEDiffuseLightingElement-dom-diffuseConstant-attr-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEDiffuseLightingElement-dom-in-attr-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEDiffuseLightingElement-dom-lighting-color-attr-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEDiffuseLightingElement-dom-surfaceScale-attr-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEDiffuseLightingElement-inherit-lighting-color-css-prop-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEDiffuseLightingElement-lighting-color-css-prop-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEDiffuseLightingElement-svgdom-diffuseConstant-prop-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEDiffuseLightingElement-svgdom-in-prop-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEDiffuseLightingElement-svgdom-surfaceScale-prop-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEDistantLightElement-dom-azimuth-attr-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEDistantLightElement-dom-elevation-attr-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEDistantLightElement-svgdom-azimuth-prop-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEDistantLightElement-svgdom-elevation-prop-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEDropShadowElement-dom-dx-attr-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEDropShadowElement-dom-dy-attr-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEDropShadowElement-dom-in-attr-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEDropShadowElement-dom-stdDeviation-attr-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEDropShadowElement-svgdom-dx-prop-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEDropShadowElement-svgdom-dy-prop-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEDropShadowElement-svgdom-in-prop-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEDropShadowElement-svgdom-stdDeviation-prop-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEGaussianBlurElement-dom-in-attr-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEGaussianBlurElement-dom-stdDeviation-attr-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updates/SVGFEGaussianBlurElement-dom-stdDeviation-call-expected.png
[modify] https://crrev.com/d1cfefaa74228627c0c62ee4f6a57b65b388d523/third_party/WebKit/LayoutTests/svg/dynamic-updat
Project Member

Comment 9 by ClusterFuzz, Dec 1 2017

ClusterFuzz has detected this issue as fixed in range 520627:520662.

Detailed report: https://clusterfuzz.com/testcase?key=5449983540330496

Fuzzer: ifratric-browserfuzzer-v3
Job Type: linux_msan_chrome
Platform Id: linux

Crash Type: Use-of-uninitialized-value
Crash Address: 
Crash State:
  sse41::blit_row_s32a_opaque
  SkARGB32_Shader_Blitter::blitRect
  SkScan::FillIRect
  
Sanitizer: memory (MSAN)

Recommended Security Severity: Medium

Regressed: https://clusterfuzz.com/revisions?job=linux_msan_chrome&range=519805:519843
Fixed: https://clusterfuzz.com/revisions?job=linux_msan_chrome&range=520627:520662

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5449983540330496

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 10 by ClusterFuzz, Dec 1 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 5449983540330496 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 11 by sheriffbot@chromium.org, Dec 1 2017

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Project Member

Comment 12 by bugdroid1@chromium.org, Dec 1 2017

The following revision refers to this bug:
  https://skia.googlesource.com/skia/+/65f6985a96ef631b033f299fc6796122013782b8

commit 65f6985a96ef631b033f299fc6796122013782b8
Author: Herbert Derby <herb@google.com>
Date: Fri Dec 01 22:21:20 2017

Initialize dst image memory for small sigma

The GPU and CPU share the same code for layout; the layout is too large for CPU. So,
the CPU code must clear some of the destination even if there would be no work to do.

Change-Id: I29a04217b620b033a01db53487dc64e377661436
BUG= chromium:789812 
Reviewed-on: https://skia-review.googlesource.com/79401
Commit-Queue: Herb Derby <herb@google.com>
Reviewed-by: Florin Malita <fmalita@chromium.org>

[modify] https://crrev.com/65f6985a96ef631b033f299fc6796122013782b8/src/core/SkBlurImageFilter.cpp

Project Member

Comment 13 by bugdroid1@chromium.org, Dec 2 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/5ae6c5cdd3e0c61f06dcd2ff2dc73f81fe44c71e

commit 5ae6c5cdd3e0c61f06dcd2ff2dc73f81fe44c71e
Author: skia-deps-roller@chromium.org <skia-deps-roller@chromium.org>
Date: Sat Dec 02 13:23:15 2017

Roll src/third_party/skia/ 713571f9a..1ec99b9b8 (56 commits)

https://skia.googlesource.com/skia.git/+log/713571f9afcf..1ec99b9b8e27

$ git log 713571f9a..1ec99b9b8 --date=short --no-merges --format='%ad %ae %s'
2017-12-02 angle-deps-roller Roll skia/third_party/externals/angle2/ 76746f9bc..d5f44c986 (1 commit)
2017-12-01 egdaniel Add cap on intel to avoid calling abs and floor on the same line in a shader.
2017-12-01 angle-deps-roller Roll skia/third_party/externals/angle2/ 361df0703..76746f9bc (1 commit)
2017-12-01 herb Initialize dst image memory for small sigma
2017-12-01 bsalomon Revert "Revert "Fix rendering of drrects with small circular inner rrects.""
2017-12-01 bsalomon Exit from GLTestAtlasTextRenderer early if GL version is not supported.
2017-11-30 bsalomon Reland "Set multitexturing image threshold for PowerVR."
2017-12-01 csmartdalton Add Store3 to Sk2f
2017-12-01 robertphillips Add explicit GPU resource allocation of deferred proxies
2017-12-01 bsalomon Revert "Fix rendering of drrects with small circular inner rrects."
2017-12-01 caryclark fix pathops handling of tiny wrapback quads and cubics
2017-11-30 bsalomon Reland "Set multitexturing threshold for NVIDIA"
2017-12-01 bsalomon Fix rendering of drrects with small circular inner rrects.
2017-12-01 mtklein add OWNERS file
2017-12-01 liyuqian Try to bypass the false-positive clang thread analysis warning
2017-11-30 mtklein add Load2() to Sk4f
2017-12-01 angle-deps-roller Roll skia/third_party/externals/angle2/ 5b18f487c..361df0703 (2 commits)
2017-12-01 halcanary Fuzz: RasterN32CanvasViaSerialization,
2017-12-01 caryclark working on skimage
2017-12-01 brianosman Remove more views code, just to simplify things
2017-12-01 brianosman Add 'Save to SKP' option to Viewer
2017-12-01 bsalomon Revert "Revert "Use a dst size threshold for multitexturing images.""
2017-12-01 angle-deps-roller Roll skia/third_party/externals/angle2/ 035419fad..5b18f487c (3 commits)
2017-12-01 scroggo Add comments explaining use of "-Wno-over-aligned"
2017-12-01 brianosman Move some bits from views to sk_app
2017-12-01 angle-deps-roller Roll skia/third_party/externals/angle2/ da854a272..035419fad (2 commits)
2017-11-30 angle-deps-roller Roll skia/third_party/externals/angle2/ 9f2a86134..da854a272 (1 commit)
2017-11-30 ethannicholas fixed a few SPIR-V generation errors
2017-11-30 benjaminwagner Remove IntelIris640 bot.
2017-11-30 reed remove read/write rawpixels
2017-11-30 scroggo Revert "Renaming and refactoring to prepare for init-once threaded backend"
2017-11-30 angle-deps-roller Roll skia/third_party/externals/angle2/ e218f15fc..9f2a86134 (1 commit)
2017-11-30 reed encode kAlpha_8 as grayalpha with sigbits for gray==1
2017-11-30 scroggo Add "-Wno-over-aligned" to Android.bp for x86 Android
2017-11-30 angle-deps-roller Roll skia/third_party/externals/angle2/ 97fa85579..e218f15fc (1 commit)
2017-11-30 liyuqian Renaming and refactoring to prepare for init-once threaded backend
2017-11-30 robertphillips Revert "Enable explicit GPU resource allocation"
2017-11-30 bsalomon Revert "Use a dst size threshold for multitexturing images."
2017-11-30 bsalomon Revert "Set multitexturing threshold for NVIDIA"
2017-11-30 bsalomon Revert "Set multitexturing image threshold for PowerVR."
2017-11-30 angle-deps-roller Roll skia/third_party/externals/angle2/ 18841310d..97fa85579 (1 commit)
2017-11-30 robertphillips Enable explicit GPU resource allocation
2017-11-30 bsalomon Set multitexturing image threshold for PowerVR.
2017-11-30 bsalomon Set multitexturing threshold for NVIDIA
2017-11-30 robertphillips Flesh out SkSurfaceCharacterization
2017-11-29 liyuqian Add a GM to test the fix in 73200
2017-11-30 benjaminwagner Promote experimental tryjob to be blocking.
2017-11-29 bsalomon Fix SkInternalAtlasTextContext to update advance the flush token after issuing each draw.
2017-11-29 csmartdalton Add "lazy" texture proxies
2017-11-30 kjlubick Turn up Nexus10 CPU frequencies
2017-11-29 mtklein bug fix in matrix color filter
2017-11-30 bsalomon Use a dst size threshold for multitexturing images.
2017-11-30 hcm Update Skia milestone to 65
2017-11-30 robertphillips Add a GrContextThreadSafeProxy to SkSurfaceCharacterization
2017-11-30 kjlubick Make cpu scaling more robust
2017-11-29 csmartdalton Make sure to visit clips and dst proxies during gather

Created with:
  roll-dep src/third_party/skia
BUG= 789812 ,769026


The AutoRoll server is located here: https://autoroll.skia.org

Documentation for the AutoRoller is here:
https://skia.googlesource.com/buildbot/+/master/autoroll/README.md

If the roll is causing failures, please contact the current sheriff, who should
be CC'd on the roll, and stop the roller if necessary.


CQ_INCLUDE_TRYBOTS=master.tryserver.blink:linux_trusty_blink_rel;master.tryserver.chromium.linux:linux_optional_gpu_tests_rel;master.tryserver.chromium.mac:mac_optional_gpu_tests_rel;master.tryserver.chromium.win:win_optional_gpu_tests_rel
TBR=allanmac@chromium.org

Change-Id: I18df2567ff439a1fdd21851d24333a5b5f5431ab
Reviewed-on: https://chromium-review.googlesource.com/805216
Reviewed-by: Skia Deps Roller <skia-deps-roller@chromium.org>
Commit-Queue: Skia Deps Roller <skia-deps-roller@chromium.org>
Cr-Commit-Position: refs/heads/master@{#521212}
[modify] https://crrev.com/5ae6c5cdd3e0c61f06dcd2ff2dc73f81fe44c71e/DEPS

Project Member

Comment 14 by sheriffbot@chromium.org, Mar 9 2018

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 15 by sheriffbot@chromium.org, Mar 27 2018

Labels: -Security_Impact-Head -M-64 M-65 Security_Impact-Stable
Labels: -ReleaseBlock-Stable

Sign in to add a comment