New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 850083 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Last visit > 30 days ago
Closed: Jun 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Abrt in quic::QuicFramer::ProcessIetfFrameData

Project Member Reported by ClusterFuzz, Jun 6 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5412059068760064

Fuzzer: libFuzzer_net_quic_stream_factory_fuzzer
Job Type: libfuzzer_chrome_asan_debug
Platform Id: linux

Crash Type: Abrt
Crash Address: 0x0539000052c2
Crash State:
  quic::QuicFramer::ProcessIetfFrameData
  quic::QuicFramer::ProcessIetfDataPacket
  quic::QuicFramer::ProcessPacket
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan_debug&range=564618:564646

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5412059068760064

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
 
Project Member

Comment 1 by ClusterFuzz, Jun 6 2018

Components: Internals>Network
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Project Member

Comment 2 by ClusterFuzz, Jun 6 2018

Cc: nedwilli...@gmail.com
Labels: ClusterFuzz-Auto-CC
Automatically adding ccs based on OWNERS file / target commit history.

If this is incorrect, please add ClusterFuzz-Wrong label.
Project Member

Comment 3 by ClusterFuzz, Jun 6 2018

Labels: Test-Predator-Auto-Owner
Owner: mpw@chromium.org
Status: Assigned (was: Untriaged)
Automatically assigning owner based on suspected regression changelist https://chromium.googlesource.com/chromium/src/+/60637aee0733db686859db89ce72b948364cb20c (Landing Recent QUIC changes until Fri May 25 16:11:25 2018 +0000).

If this is incorrect, please let us know why and apply the Test-Predator-Wrong-CLs label. If you aren't the correct owner for this issue, please unassign yourself as soon as possible so it can be re-triaged.

Comment 4 by mpw@chromium.org, Jun 6 2018

Cc: mpw@chromium.org
Owner: fkastenholz@chromium.org
Labels: -Pri-1 Pri-2
This seems to be an issue arising because not all of the IETF-QUIC format CLs were in the most recent merge. This should be addressed when the final CLs get merged. 

This has no operational impact since the affected code is reached IFF we have negotiated version-99, which we currently do not do (this is flag protected).  

Comment 6 by mpw@chromium.org, Jun 6 2018

Thanks for the quick diagnosis, Frank!  We can close this out once the rest of the current batch of IETF-QUIC format CLs are merged.
Project Member

Comment 7 by ClusterFuzz, Jun 11 2018

ClusterFuzz has detected this issue as fixed in range 565496:565508.

Detailed report: https://clusterfuzz.com/testcase?key=5412059068760064

Fuzzer: libFuzzer_net_quic_stream_factory_fuzzer
Job Type: libfuzzer_chrome_asan_debug
Platform Id: linux

Crash Type: Abrt
Crash Address: 0x0539000052c2
Crash State:
  quic::QuicFramer::ProcessIetfFrameData
  quic::QuicFramer::ProcessIetfDataPacket
  quic::QuicFramer::ProcessPacket
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan_debug&range=564618:564646
Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan_debug&range=565496:565508

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5412059068760064

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 8 by ClusterFuzz, Jun 11 2018

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 5412059068760064 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment