New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 806546 link

Starred by 3 users

Issue metadata

Status: Assigned
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Mac
Pri: 2
Type: Bug



Sign in to add a comment

Out-of-memory in expat_xml_parse_fuzzer

Project Member Reported by ClusterFuzz, Jan 27 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=6386921715269632

Fuzzer: libFuzzer_expat_xml_parse_fuzzer
Job Type: libfuzzer_chrome_msan
Platform Id: linux

Crash Type: Out-of-memory (exceeds 2048 MB)
Crash Address: 
Crash State:
  expat_xml_parse_fuzzer
  
Sanitizer: memory (MSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=411312:411446

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6386921715269632

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
 
Cc: aizatsky@chromium.org brajkumar@chromium.org
Components: Blink>XML
Labels: M-64 Test-Predator-Wrong
Owner: jochen@chromium.org
Status: Assigned (was: Untriaged)
Predator could not provide any possible suspects.

From the below CL observing some changes related to expat fuzzer, hence suspecting the same
https://chromium.googlesource.com/chromium/src/+log/27e6d33fae535f032d7abcad36a71e690ab0ae55..a5be776a37c46f6a8792756cec52973d4390a845?pretty=fuller&n=10000

Suspect CL: https://chromium.googlesource.com/chromium/src/+/7755511101817d4baed54f361622e3084147079f

jochen@/aizatsky@ -- Could you please check whether this is caused with respect to your change, if not please help us in assigning it to the right owner.

Note: aizatsky last visit was >30 days ago, hence assigning to the reviewer of the file

Thanks!
Labels: -Pri-1 Pri-2

Comment 3 by jochen@chromium.org, Jan 29 2018

Cc: mmoroz@chromium.org jochen@chromium.org
Owner: nick@chromium.org

Comment 4 by jochen@chromium.org, Jan 29 2018

Cc: nick@chromium.org
Owner: nasko@chromium.org
Nick is out, Dominic no longer is with Chrome, so I guess you're on the hook Nasko for libexpat

Comment 5 by nasko@chromium.org, Mar 28 2018

Cc: dcheng@chromium.org
Owner: dcheng@chromium.org
Over to dcheng@, who is tracking some xml parser usage in Chromium and is more familiar with this area.

Comment 6 by mmoroz@chromium.org, Mar 28 2018

Cc: schenney@chromium.org
Project Member

Comment 7 by ClusterFuzz, Apr 13 2018

Labels: OS-Mac
Project Member

Comment 8 by ClusterFuzz, Dec 1

Labels: -Reproducible Unreproducible
ClusterFuzz testcase 6386921715269632 appears to be flaky, updating reproducibility label.
Labels: -Unreproducible Reproducible
Please ignore the last comment about testcase being unreproducible. The testcase is still reproducible. This happened due to a code refactoring on ClusterFuzz side, and the underlying root cause is now fixed. Resetting the label back to Reproducible. Sorry about the inconvenience caused from these incorrect notifications.
Please ignore the last comment about testcase being unreproducible. The testcase is still reproducible. This happened due to a code refactoring on ClusterFuzz side, and the underlying root cause is now fixed. Resetting the label back to Reproducible. Sorry about the inconvenience caused from these incorrect notifications.

Sign in to add a comment