Breakpoint in base::PickleIterator::ReadLong |
|||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5462484657635328 Fuzzer: libFuzzer_pickle_fuzzer Job Type: windows_libfuzzer_chrome_asan Platform Id: windows Crash Type: Breakpoint Crash Address: 0x000000000000 Crash State: base::PickleIterator::ReadLong pickle_fuzzer.cc Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=windows_libfuzzer_chrome_asan&range=610080:610107 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5462484657635328 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing_on_windows.md for more information.
,
Nov 21
Automatically assigning owner based on suspected regression changelist https://chromium.googlesource.com/chromium/src/+/7404c058244b48008231f057b9e779e07f49eebc (Add fuzzer for base::PickleIterator.). If this is incorrect, please let us know why and apply the Test-Predator-Wrong-CLs label. If you aren't the correct owner for this issue, please unassign yourself as soon as possible so it can be re-triaged.
,
Nov 21
Jonathan, this is another Windows specific crash :)
,
Nov 26
This crash occurs very frequently on windows platform and is likely preventing the fuzzer pickle_fuzzer from making much progress. Fixing this will allow more bugs to be found. Marking this bug as a blocker for next Beta release. If this is incorrect, please add ClusterFuzz-Wrong label and remove the ReleaseBlock-Beta label.
,
Nov 26
Sigh! sizeof(long) == 4 on windows (https://msdn.microsoft.com/en-us/library/s3f49ktz.aspx), so the checked_cast<long>(int64_t) will CHECK-fail on anything outside the int32 range. This appears to be intentional behaviour.
,
Nov 27
-RBB, not a release issue.
,
Nov 27
,
Dec 1
ClusterFuzz testcase 5462484657635328 appears to be flaky, updating reproducibility label.
,
Dec 1
Please ignore the last comment about testcase being unreproducible. The testcase is still reproducible. This happened due to a code refactoring on ClusterFuzz side, and the underlying root cause is now fixed. Resetting the label back to Reproducible. Sorry about the inconvenience caused from these incorrect notifications.
,
Dec 14
The documentation for reproducing on Windows has been moved to https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md |
|||||||
►
Sign in to add a comment |
|||||||
Comment 1 by ClusterFuzz
, Nov 21Labels: Test-Predator-Auto-Components