New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 807348 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Feb 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Regression



Sign in to add a comment

Null-dereference WRITE in sw::FrameBufferX11::~FrameBufferX11

Project Member Reported by ClusterFuzz, Jan 30 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=6027547641643008

Fuzzer: puzzor
Job Type: linux_asan_chrome_mp
Platform Id: linux

Crash Type: Null-dereference WRITE
Crash Address: 0x000000000010
Crash State:
  sw::FrameBufferX11::~FrameBufferX11
  egl::WindowSurface::swap
  gpu::PassThroughImageTransportSurface::SwapBuffers
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_mp&range=532825:532827

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6027547641643008

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Jan 30 2018

Labels: M-65 ReleaseBlock-Beta ClusterFuzz-Top-Crash
Testcase 6027547641643008 is a top crash on ClusterFuzz for linux platform. Please prioritize fixing this crash.

Marking this crash as a Beta release blocker.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Comment 2 Deleted

Cc: brajkumar@chromium.org
Components: Internals>GPU
Labels: -Type-Bug Test-Predator-Wrong Type-Bug-Regression
Owner: penghuang@chromium.org
Status: Assigned (was: Untriaged)
Predator and CL could not provide any possible suspects.

Using Code Search for the file, "pass_through_image_transport_surface.cc" and observed there was some recent changes for the below file.

Suspect CL: https://chromium.googlesource.com/chromium/src/+/6bf92778c48f4041a2e21c29c89bfc4683e9d34d%5E%21/gpu/ipc/service/pass_through_image_transport_surface.cc

penghuang@ -- Could you please check whether this is caused with respect to your change, if not please help us in assigning it to the right owner.

Thanks!

Cc: penghuang@chromium.org
Owner: sugoi@chromium.org
I don't think it is related to my change. 

sugoi, could you please take a look this issue? Thanks.
Cc: ifratric@google.com
 Issue 807730  has been merged into this issue.

Comment 6 by sugoi@chromium.org, Feb 1 2018

Cc: sugoi@chromium.org
Owner: capn@chromium.org
capn@ just investigated  issue 807079  which was in the same class as this issue. capn@, can you have a quick look?
M65 Beta promotion is coming soon and your bug is labelled as Beta ReleaseBlock, pls make sure to land the fix and request a merge to M65 branch 3325 ASAP (merge has to be done latest by Monday, 02/05 @ 1:00 PM PT). Thank you.

Comment 8 by capn@chromium.org, Feb 2 2018

Status: WontFix (was: Assigned)
I couldn't reproduce this locally, and clusterfuzz also can no longer reproduce this. I'm fairly confident that this was just an issue with the X11 setup of the clusterfuzz machine this was running on, which we can't really recover from anyway so crashing the GPU process is acceptable.
Project Member

Comment 9 by ClusterFuzz, Feb 9 2018

Labels: Needs-Feedback
ClusterFuzz testcase 6222763568922624 is still reproducing on tip-of-tree build (trunk).

If this testcase was not reproducible locally or unworkable, ignore this notification and we will file another bug soon with hopefully a better and workable testcase.

Otherwise, if this is not intended to be fixed (e.g. this is an intentional crash), please add ClusterFuzz-Ignore label to prevent future bug filing with similar crash stacktrace.

Sign in to add a comment