New issue
Advanced search Search tips

Issue 796839 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 801987
Owner:
Closed: Jan 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 3
Type: Bug



Sign in to add a comment

Integer-overflow in ConstantUnion::operator+

Project Member Reported by ClusterFuzz, Dec 21 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5525590617882624

Fuzzer: libFuzzer_swiftshader_vertex_routine_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  ConstantUnion::operator+
  TIntermConstantUnion::fold
  TIntermediate::addBinaryMath
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=521492:521536

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5525590617882624

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
 
Project Member

Comment 1 by ClusterFuzz, Dec 21 2017

Components: Internals>GPU>SwiftShader
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Labels: M-65 Test-Predator-Wrong
Owner: capn@chromium.org
Status: Assigned (was: Untriaged)
Since it is related to Swiftshader component, assigning it to capn@

capn@ could you please look into it


Thank You...

Comment 3 by capn@chromium.org, Dec 22 2017

Cc: sugoi@chromium.org
Labels: -Pri-2 Pri-3
The integer overflow is also undefined behavior in the GLSL language that this is compiling, so it's benign.

Casting to unsigned and then back to signed would silence UBSAN since unsigned overflow is well defined.
Project Member

Comment 4 by ClusterFuzz, Jan 13 2018

ClusterFuzz has detected this issue as fixed in range 529109:529114.

Detailed report: https://clusterfuzz.com/testcase?key=5525590617882624

Fuzzer: libFuzzer_swiftshader_vertex_routine_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  ConstantUnion::operator+
  TIntermConstantUnion::fold
  TIntermediate::addBinaryMath
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=521492:521536
Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=529109:529114

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5525590617882624

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by ClusterFuzz, Jan 13 2018

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 5525590617882624 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Comment 6 by capn@chromium.org, Jan 16 2018

Mergedinto: 801987
Status: Duplicate (was: Verified)

Sign in to add a comment