New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 801823 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Jun 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 3
Type: Bug



Sign in to add a comment

Null-dereference READ in TParseContext::addFunctionCallOrMethod

Project Member Reported by ClusterFuzz, Jan 13 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=6494208218365952

Fuzzer: libFuzzer_swiftshader_vertex_routine_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Null-dereference READ
Crash Address: 0x000000000000
Crash State:
  TParseContext::addFunctionCallOrMethod
  yyparse
  PaParseStrings
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=521492:521536

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6494208218365952

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
 
Project Member

Comment 1 by ClusterFuzz, Jan 13 2018

Components: Internals>GPU>SwiftShader
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Cc: capn@chromium.org brajkumar@chromium.org
Labels: M-65 Test-Predator-Wrong CF-NeedsTriage
Unable to find actual suspect through code search and also from the provided CL, hence marking it as untriaged.

capn@ Could you please take a look in to this issue?

Thanks!

Comment 3 by piman@chromium.org, Jan 19 2018

Owner: capn@chromium.org
Status: Assigned (was: Untriaged)

Comment 4 by sadrul@chromium.org, Feb 26 2018

gpu triage: ping on idle p1 bug.

Comment 5 by capn@chromium.org, May 22 2018

Labels: -Pri-1 Pri-3
This is just a GPU process crash for a fabricated edge case, so it's not very high priority. We'll also replace the GLSL compiler with glslang at some point, so it's probably not worth spending time on this.
Project Member

Comment 6 by ClusterFuzz, Jun 15 2018

ClusterFuzz has detected this issue as fixed in range 567530:567542.

Detailed report: https://clusterfuzz.com/testcase?key=6494208218365952

Fuzzer: libFuzzer_swiftshader_vertex_routine_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Null-dereference READ
Crash Address: 0x000000000000
Crash State:
  TParseContext::addFunctionCallOrMethod
  yyparse
  PaParseStrings
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=521492:521536
Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=567530:567542

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6494208218365952

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Comment 7 by capn@chromium.org, Jun 15 2018

Possibly got fixed by https://swiftshader-review.googlesource.com/19308
Project Member

Comment 8 by ClusterFuzz, Jun 16 2018

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 6494208218365952 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment