New issue
Advanced search Search tips

Issue 837259 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Apr 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug-Regression



Sign in to add a comment

Float-cast-overflow in blink::CanvasRenderingContext2DState::UpdateLineDash

Project Member Reported by ClusterFuzz, Apr 26 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5215854682439680

Fuzzer: inferno_twister
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Float-cast-overflow
Crash Address: 
Crash State:
  blink::CanvasRenderingContext2DState::UpdateLineDash
  blink::CanvasRenderingContext2DState::GetFlags
  Draw<
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=552707:552711

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5215854682439680

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Apr 26 2018

Components: Blink>Canvas
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Cc: jochen@chromium.org pnangunoori@chromium.org
Labels: -Type-Bug M-68 Test-Predator-Wrong Type-Bug-Regression
Owner: koten...@yandex-team.ru
Status: Assigned (was: Untriaged)
Predator and CL could not provide any possible suspects.
Using the code search for the file, “canvas_rendering_context_2d_state.cc” assigning to concern owner from GIT revision log.
Suspecting Commit#
https://chromium.googlesource.com/chromium/src/+/0bcc52beef639e1516a0192eb25520bc0cb37949

@kotenkov -- Could you please look into this issue, kindly reassign if it has nothing to do with your changes.

Also, CC'ing the reviewer of the above CL.

Thank You.

Project Member

Comment 3 by ClusterFuzz, Apr 27 2018

ClusterFuzz has detected this issue as fixed in range 554111:554115.

Detailed report: https://clusterfuzz.com/testcase?key=5215854682439680

Fuzzer: inferno_twister
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Float-cast-overflow
Crash Address: 
Crash State:
  blink::CanvasRenderingContext2DState::UpdateLineDash
  blink::CanvasRenderingContext2DState::GetFlags
  Draw<
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=552707:552711
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=554111:554115

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5215854682439680

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 4 by ClusterFuzz, Apr 27 2018

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 5215854682439680 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment