New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 906417 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Nov 21
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows
Pri: 1
Type: Bug



Sign in to add a comment

Out-of-memory in dawn_spirv_cross_msl_fast_fuzzer

Project Member Reported by ClusterFuzz, Nov 18

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5075475774570496

Fuzzer: libFuzzer_dawn_spirv_cross_msl_fast_fuzzer
Job Type: libfuzzer_chrome_msan
Platform Id: linux

Crash Type: Out-of-memory (exceeds 2048 MB)
Crash Address: 
Crash State:
  dawn_spirv_cross_msl_fast_fuzzer
  
Sanitizer: memory (MSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=607423:607447

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5075475774570496

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
 
Project Member

Comment 1 by ClusterFuzz, Nov 18

Labels: OS-Windows
Project Member

Comment 2 by ClusterFuzz, Nov 18

Cc: kainino@chromium.org cwallez@chromium.org
Labels: ClusterFuzz-Auto-CC
Automatically adding ccs based on OWNERS file / target commit history.

If this is incorrect, please add ClusterFuzz-Wrong label.
Cc: dsinclair@chromium.org fjhenigman@chromium.org
Owner: rharrison@chromium.org
Status: Assigned (was: Untriaged)
Components: Internals>GPU>Dawn
So running just this test case does not reproduce the issue, atleast on a non-MSAN Linux build. Specifically it fast fails due to an invalid SPIRV format error.

This makes me suspect that the issue is actually something with the fuzzing target, i.e. memory being retained/leaked between test cases.
This might be resolved by https://dawn-review.googlesource.com/c/dawn/+/2521. So I will rerun this test case once that CL has rolled into Chromium
Project Member

Comment 7 by ClusterFuzz, Nov 21

ClusterFuzz has detected this issue as fixed in range 609745:609746.

Detailed report: https://clusterfuzz.com/testcase?key=5075475774570496

Fuzzer: libFuzzer_dawn_spirv_cross_msl_fast_fuzzer
Job Type: libfuzzer_chrome_msan
Platform Id: linux

Crash Type: Out-of-memory (exceeds 2048 MB)
Crash Address: 
Crash State:
  dawn_spirv_cross_msl_fast_fuzzer
  
Sanitizer: memory (MSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=607423:607447
Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=609745:609746

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5075475774570496

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 8 by ClusterFuzz, Nov 21

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 5075475774570496 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment