New issue
Advanced search Search tips

Issue 825476 link

Starred by 3 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Apr 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Null-dereference WRITE in /build/glibc-Cl5G7W/glibc-NUMBER/string/../sysdeps/x86_64/multiarch/memcpy-sse2-

Project Member Reported by ClusterFuzz, Mar 24 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=6480051512803328

Fuzzer: inferno_twister
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Null-dereference WRITE
Crash Address: 0x000000000000
Crash State:
  /build/glibc-Cl5G7W/glibc-NUMBER/string/../sysdeps/x86_64/multiarch/memcpy-sse2-
  SkDynamicMemoryWStream::copyToAndReset
  printing::PdfCompositorImpl::CompositeToPdf
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=523880:523906

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6480051512803328

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Mar 24 2018

Components: Internals>Skia
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Project Member

Comment 2 by ClusterFuzz, Mar 24 2018

Cc: herb@google.com robertph...@google.com reed@google.com
Labels: Test-Predator-Auto-CC
Automatically adding ccs based on suspected regression changelists:

Revert "Revert "impl SkSerial picture procs"" by reed@google.com - https://skia.googlesource.com/skia/+/45ab630045ec72dcc0c4546cc1e96ac518897896

Simplify image clearing by herb@google.com - https://skia.googlesource.com/skia/+/661c542e4ad2626d872e9321392a56c99e1c1011

Add stubbed out GrContext by robertphillips@google.com - https://skia.googlesource.com/skia/+/e42edcc8ef257d4c430344d6d208e994f20f9320

If this is incorrect, please let us know why and apply the Test-Predator-Wrong-CLs label.

Comment 3 by herb@google.com, Mar 25 2018

Cc: halcanary@google.com
Project Member

Comment 4 by bugdroid1@chromium.org, Mar 29 2018

The following revision refers to this bug:
  https://skia.googlesource.com/skia/+/c3bc425bd4d630f4c6b69f38473fc69b77a1d5b9

commit c3bc425bd4d630f4c6b69f38473fc69b77a1d5b9
Author: Hal Canary <halcanary@google.com>
Date: Thu Mar 29 15:46:45 2018

SkDynamicMemoryWStream: clean up, asserts, etc.

BUG= chromium:825476 
Change-Id: Ied7d5e8313781821acc778d784ecade46b93ca22
Reviewed-on: https://skia-review.googlesource.com/116860
Reviewed-by: Herb Derby <herb@google.com>
Commit-Queue: Hal Canary <halcanary@google.com>

[modify] https://crrev.com/c3bc425bd4d630f4c6b69f38473fc69b77a1d5b9/src/core/SkStream.cpp

Project Member

Comment 5 by bugdroid1@chromium.org, Mar 29 2018

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/555410b7ce91ef5cf31f480803c01c93d95c28cc

commit 555410b7ce91ef5cf31f480803c01c93d95c28cc
Author: skia-chromium-autoroll@skia-buildbots.google.com.iam.gserviceaccount.com <skia-chromium-autoroll@skia-buildbots.google.com.iam.gserviceaccount.com>
Date: Thu Mar 29 18:34:24 2018

Roll src/third_party/skia/ 702a7dfc9..c3bc425bd (8 commits)

https://skia.googlesource.com/skia.git/+log/702a7dfc91f9..c3bc425bd4d6

$ git log 702a7dfc9..c3bc425bd --date=short --no-merges --format='%ad %ae %s'
2018-03-28 halcanary SkDynamicMemoryWStream: clean up, asserts, etc.
2018-03-28 senorblanco Reland "GrTessellator: hang fix."
2018-03-29 angle-skia-autoroll Roll skia/third_party/externals/angle2/ a3b220f36..96310cdad (1 commit)
2018-03-29 skcms-skia-autoroll Roll skia/third_party/externals/skcms/ 5678b9d6a..3f0009288 (1 commit)
2018-03-28 kdonev Fixing build with SK_IGNORE_TO_STRING defined.
2018-03-28 ethannicholas fixed type mismatches in SkSL comparison operators
2018-03-28 csmartdalton Don't use gl_FragCoord on legacy Tegra hardware
2018-03-29 mtklein Revert "GrTessellator: hang fix."

Created with:
  roll-dep src/third_party/skia
BUG= chromium:825476 , chromium:802896 , chromium:802896 


The AutoRoll server is located here: https://autoroll.skia.org

Documentation for the AutoRoller is here:
https://skia.googlesource.com/buildbot/+/master/autoroll/README.md

If the roll is causing failures, please contact the current sheriff, who should
be CC'd on the roll, and stop the roller if necessary.


CQ_INCLUDE_TRYBOTS=master.tryserver.blink:linux_trusty_blink_rel;luci.chromium.try:android_optional_gpu_tests_rel;luci.chromium.try:linux_optional_gpu_tests_rel;luci.chromium.try:mac_optional_gpu_tests_rel;master.tryserver.chromium.win:win_optional_gpu_tests_rel
TBR=mtklein@chromium.org

Change-Id: Iad642d09e901c9392b9a24294e457a74dbe94a97
Reviewed-on: https://chromium-review.googlesource.com/986464
Reviewed-by: skia-chromium-autoroll <skia-chromium-autoroll@skia-buildbots.google.com.iam.gserviceaccount.com>
Commit-Queue: Mike Klein <mtklein@chromium.org>
Commit-Queue: skia-chromium-autoroll <skia-chromium-autoroll@skia-buildbots.google.com.iam.gserviceaccount.com>
Cr-Commit-Position: refs/heads/master@{#546869}
[modify] https://crrev.com/555410b7ce91ef5cf31f480803c01c93d95c28cc/DEPS

Project Member

Comment 6 by ClusterFuzz, Apr 12 2018

Status: WontFix (was: Untriaged)
ClusterFuzz testcase 6480051512803328 is flaky and no longer crashes, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment