New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 860845 link

Starred by 2 users

Issue metadata

Status: Verified
Owner:
Last visit > 30 days ago
Closed: Jul 9
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

CHECK failure: patch_size <= kMaxImageSize * 3 in imposed_ensemble_matcher_fuzzer.cc

Project Member Reported by ClusterFuzz, Jul 6

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5597713031495680

Fuzzer: libFuzzer_zucchini_imposed_ensemble_matcher_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  patch_size <= kMaxImageSize * 3 in imposed_ensemble_matcher_fuzzer.cc
  TestOneProtoInput
  TestOneProtoInput
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=572200:572205

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5597713031495680

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
 
Project Member

Comment 1 by ClusterFuzz, Jul 6

Components: Internals>Installer>Diff
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Project Member

Comment 2 by ClusterFuzz, Jul 6

Cc: ckitagawa@chromium.org
Labels: ClusterFuzz-Auto-CC
Automatically adding ccs based on OWNERS file / target commit history.

If this is incorrect, please add ClusterFuzz-Wrong label.
Project Member

Comment 3 by ClusterFuzz, Jul 6

Labels: Test-Predator-Auto-Owner
Owner: ckitagawa@chromium.org
Status: Assigned (was: Untriaged)
Automatically assigning owner based on suspected regression changelist https://chromium.googlesource.com/chromium/src/+/f7b526674131a74a43ba13394f1c4819cac9c2d2 ([Zucchini] imposed_ensemble_matcher Fuzzer).

If this is incorrect, please let us know why and apply the Test-Predator-Wrong-CLs label. If you aren't the correct owner for this issue, please unassign yourself as soon as possible so it can be re-triaged.
Project Member

Comment 4 by bugdroid1@chromium.org, Jul 9

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/71ac85257f083f1d3ceded06f1d66992e033d389

commit 71ac85257f083f1d3ceded06f1d66992e033d389
Author: Calder Kitagawa <ckitagawa@chromium.org>
Date: Mon Jul 09 18:28:43 2018

[Zucchini] Remove imposed_ensemble_matcher_fuzzer size check

This check isn't very helpful. It only finds pathological but valid
situations. Typically, the resulting patch is very compressible and
this only checks the uncompressed size, which is inflated due to having
many headers for ZTF and Raw regions.

Bug:  860845 
Change-Id: I5747e787a1c9888c4ef70d8449572517669f39cd
Reviewed-on: https://chromium-review.googlesource.com/1128810
Commit-Queue: Calder Kitagawa <ckitagawa@chromium.org>
Reviewed-by: Samuel Huang <huangs@chromium.org>
Cr-Commit-Position: refs/heads/master@{#573372}
[modify] https://crrev.com/71ac85257f083f1d3ceded06f1d66992e033d389/components/zucchini/fuzzers/imposed_ensemble_matcher_fuzzer.cc

Status: Fixed (was: Assigned)
Project Member

Comment 6 by ClusterFuzz, Jul 10

ClusterFuzz has detected this issue as fixed in range 573369:573372.

Detailed report: https://clusterfuzz.com/testcase?key=5597713031495680

Fuzzer: libFuzzer_zucchini_imposed_ensemble_matcher_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  patch_size <= kMaxImageSize * 3 in imposed_ensemble_matcher_fuzzer.cc
  TestOneProtoInput
  TestOneProtoInput
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=572200:572205
Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=573369:573372

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5597713031495680

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 7 by ClusterFuzz, Jul 10

Labels: ClusterFuzz-Verified
Status: Verified (was: Fixed)
ClusterFuzz testcase 5597713031495680 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment