New issue
Advanced search Search tips

Issue 820043 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Mar 2018
Cc:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 2
Type: Bug



Sign in to add a comment

Direct-leak in BZ2_bzDecompressInit

Project Member Reported by ClusterFuzz, Mar 8 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=4735816279261184

Fuzzer: libFuzzer_puffin_fuzzer
Job Type: libfuzzer_asan_chromeos
Platform Id: linux

Crash Type: Direct-leak
Crash Address: 
Crash State:
  BZ2_bzDecompressInit
  bsdiff::BZ2Decompressor::SetInputData
  bsdiff::BsdiffPatchReader::Init
  
Sanitizer: address (ASAN)

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4735816279261184

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
 
Owner: ahass...@chromium.org
Status: Assigned (was: Untriaged)
Project Member

Comment 2 by bugdroid1@chromium.org, Mar 17 2018

The following revision refers to this bug:
  https://chromium.googlesource.com/chromiumos/overlays/chromiumos-overlay/+/6afb65dd05101b0db8e7ec1f6a8d56055c860624

commit 6afb65dd05101b0db8e7ec1f6a8d56055c860624
Author: Amin Hassani <ahassani@google.com>
Date: Sat Mar 17 01:31:18 2018

bsdiff: Mark as stable

Some new fuzzer problems were fixed in the bsdiff, uprev so we can test the new
changes.

The fixes were:
https://android-review.googlesource.com/c/platform/external/bsdiff/+/638404
https://android-review.googlesource.com/c/platform/external/bsdiff/+/638402
https://android-review.googlesource.com/c/platform/external/bsdiff/+/638401

TEST=unittest
BUG= chromium:820043 
BUG= chromium:819956 
BUG= chromium:818174 

Change-Id: Ifa8d0d66d82bc09b81bb71bae082406af3eb662d
Reviewed-on: https://chromium-review.googlesource.com/967008
Commit-Ready: Amin Hassani <ahassani@chromium.org>
Tested-by: Amin Hassani <ahassani@chromium.org>
Reviewed-by: Mike Frysinger <vapier@chromium.org>

[rename] https://crrev.com/6afb65dd05101b0db8e7ec1f6a8d56055c860624/dev-util/bsdiff/bsdiff-4.3.1-r12.ebuild

Project Member

Comment 3 by ClusterFuzz, Mar 21 2018

Status: WontFix (was: Assigned)
ClusterFuzz testcase 4735816279261184 is flaky and no longer crashes, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Status: Verified (was: WontFix)
I think this was incorrectly marked WontFix because of an issue with builds on ClusterFuzz.
Cc: -manojgupta@google.com manojgupta@chromium.org
Project Member

Comment 6 by ClusterFuzz, Oct 25

ClusterFuzz has detected this issue as fixed in range 2387382:2403554.

Detailed report: https://clusterfuzz.com/testcase?key=4735816279261184

Fuzzer: libFuzzer_chromeos_puffin_fuzzer
Job Type: libfuzzer_asan_chromeos
Platform Id: linux

Crash Type: Direct-leak
Crash Address: 
Crash State:
  BZ2_bzDecompressInit
  bsdiff::BZ2Decompressor::SetInputData
  bsdiff::BsdiffPatchReader::Init
  
Sanitizer: address (ASAN)

Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_asan_chromeos&range=2387382:2403554

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4735816279261184

See https://chromium.googlesource.com/chromiumos/docs/+/master/fuzzing.md#Reproducing-crashes-from-ClusterFuzz for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Sign in to add a comment