New issue
Advanced search Search tips

Issue 834546 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Apr 2018
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Mac
Pri: 1
Type: Bug

Blocking:
issue 62400



Sign in to add a comment

Timeout in pdf_codec_tiff_fuzzer

Project Member Reported by ClusterFuzz, Apr 19 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5982239930974208

Fuzzer: libFuzzer_pdf_codec_tiff_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: Timeout (exceeds 25 secs)
Crash Address: 
Crash State:
  pdf_codec_tiff_fuzzer
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan&range=422880:422991

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5982239930974208

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
 
Project Member

Comment 1 by ClusterFuzz, Apr 19 2018

Components: Internals>Plugins>PDF
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Project Member

Comment 2 by ClusterFuzz, Apr 19 2018

Labels: OS-Mac
Blocking: 62400
Owner: rharrison@chromium.org
Status: Assigned (was: Untriaged)
XFA, I will take a look
Status: Started (was: Assigned)
Looking into this a bit, it is looks like the input includes some pathelogically bad JPEG data that is causing libTIFF to do a lot of scanline operations.

Though I cannot reproduce the timeouts being seen.

I am currently in the process of updating libtiff to 4.0.9. Will take another look at this once that lands, but I suspect this is a WontFix, since it is just hard inputs.
Labels: ClusterFuzz-Ignore
Status: WontFix (was: Started)
With 4.0.9, I cannot reproduce the timeout issue locally, though under profiling I can see that there is a lot of scanline operations occurring in libtiff. As mentioned before I think this is just a pathologically bad input for libtiff and there isn't much to do, since it does complete
Project Member

Comment 6 by ClusterFuzz, May 4 2018

Labels: Needs-Feedback
ClusterFuzz testcase 5982239930974208 is still reproducing on tip-of-tree build (trunk).

If this testcase was not reproducible locally or unworkable, ignore this notification and we will file another bug soon with hopefully a better and workable testcase.

Otherwise, if this is not intended to be fixed (e.g. this is an intentional crash), please add ClusterFuzz-Ignore label to prevent future bug filing with similar crash stacktrace.
Labels: -Needs-Feedback
I already marked this as WontFix & ClusterFuzz-Ignore. It is just a really hard to process JPEG for libtiff.
Project Member

Comment 8 by ClusterFuzz, Nov 1

Labels: OS-Windows
Project Member

Comment 9 by ClusterFuzz, Dec 1

Labels: -Reproducible Unreproducible
ClusterFuzz testcase 5982239930974208 appears to be flaky, updating reproducibility label.

Sign in to add a comment