New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 803020 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Jan 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Chrome , Mac
Pri: 2
Type: Bug



Sign in to add a comment

Out-of-memory in sfntly_fuzzer

Project Member Reported by ClusterFuzz, Jan 17 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5493446612877312

Fuzzer: libFuzzer_sfntly_fuzzer
Job Type: libfuzzer_chrome_msan
Platform Id: linux

Crash Type: Out-of-memory (exceeds 2048 MB)
Crash Address: 
Crash State:
  sfntly_fuzzer
  
Sanitizer: memory (MSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=414243:414324

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5493446612877312

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
 
Cc: brajkumar@chromium.org
Components: Internals>Skia>PDF
Labels: -Type-Bug M-64 Test-Predator-Wrong Type-Bug-Regression
Owner: thestig@chromium.org
Status: Assigned (was: Untriaged)
From the above regression range suspecting the below CL
https://chromium.googlesource.com/chromium/src/+/05192643e8bfe9ece91d32bd6084f5ccfe33f5a4

thestig@, could you please take a look in to this issue?

Thanks!
Cc: behdad@chromium.org
Labels: -Pri-1 -Type-Bug-Regression -M-64 OS-Chrome OS-Mac OS-Windows Pri-2 Type-Bug
Status: Started (was: Assigned)
Need to validate the numSizes field in EblcTable::Builder::Initialize().
Project Member

Comment 3 by bugdroid1@chromium.org, Jan 20 2018

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/286c80467ef26401c15d42ad93d26f4c5cac471d

commit 286c80467ef26401c15d42ad93d26f4c5cac471d
Author: Lei Zhang <thestig@chromium.org>
Date: Sat Jan 20 01:32:20 2018

Roll DEPS for sfntly 2439bd0..16f3404

16f3404 Merge pull request #95 from leizleiz/eblc-validate
bc830a8 Validate EBLC table's numSizes field.
b553114 fix #52 OTS parsing error (#54)
8c0954e Update README.md (#94)
34db4db Document the inactive status of the project (#91)
7c4b837 Fix endless loop in FontMath.log2. (#85)
6b0889d Rescue the old wiki pages from web.archive.org. (#87)

BUG= 803020 
TBR=behdad@chromium.org

Change-Id: Ie849670d0e5f653cdc810ecbe19ab82b09efcbf4
Reviewed-on: https://chromium-review.googlesource.com/877320
Reviewed-by: Lei Zhang <thestig@chromium.org>
Commit-Queue: Lei Zhang <thestig@chromium.org>
Cr-Commit-Position: refs/heads/master@{#530719}
[modify] https://crrev.com/286c80467ef26401c15d42ad93d26f4c5cac471d/DEPS

Status: Fixed (was: Started)
Project Member

Comment 5 by ClusterFuzz, Jan 20 2018

ClusterFuzz has detected this issue as fixed in range 530703:530719.

Detailed report: https://clusterfuzz.com/testcase?key=5493446612877312

Fuzzer: libFuzzer_sfntly_fuzzer
Job Type: libfuzzer_chrome_msan
Platform Id: linux

Crash Type: Out-of-memory (exceeds 2048 MB)
Crash Address: 
Crash State:
  sfntly_fuzzer
  
Sanitizer: memory (MSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=414243:414324
Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=530703:530719

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5493446612877312

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 6 by ClusterFuzz, Jan 20 2018

Labels: ClusterFuzz-Verified
Status: Verified (was: Fixed)
ClusterFuzz testcase 5493446612877312 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment