Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(105)

Issue 1776323002: [libfuzzer] Add fuzzer for FT_New_Memory_Face() from third_party/freetype2.

Created:
4 years, 9 months ago by mmoroz
Modified:
4 years, 9 months ago
CC:
chromium-reviews
Base URL:
https://chromium.googlesource.com/chromium/src.git@master
Target Ref:
refs/pending/heads/master
Project:
chromium
Visibility:
Public.

Description

[libfuzzer] Add fuzzer for FT_New_Memory_Face() from third_party/freetype2. R=aizatsky@chromium.org, inferno@chromium.org, krasin@chromium.org BUG=569578

Patch Set 1 #

Total comments: 5

Patch Set 2 : Fix the nit. #

Unified diffs Side-by-side diffs Delta from patch set Stats (+64 lines, -0 lines) Patch
M testing/libfuzzer/fuzzers/BUILD.gn View 1 chunk +9 lines, -0 lines 0 comments Download
A testing/libfuzzer/fuzzers/ft_new_memory_face_fuzzer.cc View 1 1 chunk +55 lines, -0 lines 0 comments Download

Messages

Total messages: 14 (3 generated)
mmoroz
4 years, 9 months ago (2016-03-09 16:54:56 UTC) #1
inferno
lgtm. +cc bungeman@ for this freetype review. https://codereview.chromium.org/1776323002/diff/1/testing/libfuzzer/fuzzers/ft_new_memory_face_fuzzer.cc File testing/libfuzzer/fuzzers/ft_new_memory_face_fuzzer.cc (right): https://codereview.chromium.org/1776323002/diff/1/testing/libfuzzer/fuzzers/ft_new_memory_face_fuzzer.cc#newcode12 testing/libfuzzer/fuzzers/ft_new_memory_face_fuzzer.cc:12: FT_Error g_init_freetype_result; ...
4 years, 9 months ago (2016-03-09 17:16:43 UTC) #4
bungeman-chromium
https://codereview.chromium.org/1776323002/diff/1/testing/libfuzzer/fuzzers/BUILD.gn File testing/libfuzzer/fuzzers/BUILD.gn (right): https://codereview.chromium.org/1776323002/diff/1/testing/libfuzzer/fuzzers/BUILD.gn#newcode332 testing/libfuzzer/fuzzers/BUILD.gn:332: "//third_party/freetype2", While this is the freetype we run the ...
4 years, 9 months ago (2016-03-09 18:34:35 UTC) #5
bungeman-chromium
https://codereview.chromium.org/1776323002/diff/1/testing/libfuzzer/fuzzers/BUILD.gn File testing/libfuzzer/fuzzers/BUILD.gn (right): https://codereview.chromium.org/1776323002/diff/1/testing/libfuzzer/fuzzers/BUILD.gn#newcode332 testing/libfuzzer/fuzzers/BUILD.gn:332: "//third_party/freetype2", On 2016/03/09 18:34:35, bungeman2 wrote: > While this ...
4 years, 9 months ago (2016-03-09 18:49:26 UTC) #6
aarya
4 years, 9 months ago (2016-03-09 22:14:18 UTC) #8
aarya
On 2016/03/09 22:14:18, aarya wrote: bungeman@, for context, https://github.com/google/libfuzzer-bot/blob/master/freetype/README.md is not continuous testing. It is ...
4 years, 9 months ago (2016-03-09 22:17:04 UTC) #9
bungeman-chromium
On 2016/03/09 22:17:04, aarya wrote: > On 2016/03/09 22:14:18, aarya wrote: > > bungeman@, for ...
4 years, 9 months ago (2016-03-09 22:38:17 UTC) #10
mmoroz
Thanks bungeman@. As Abhishek already said we care about the code which is used in ...
4 years, 9 months ago (2016-03-10 09:36:58 UTC) #11
mmoroz
https://codereview.chromium.org/1776323002/diff/1/testing/libfuzzer/fuzzers/ft_new_memory_face_fuzzer.cc File testing/libfuzzer/fuzzers/ft_new_memory_face_fuzzer.cc (right): https://codereview.chromium.org/1776323002/diff/1/testing/libfuzzer/fuzzers/ft_new_memory_face_fuzzer.cc#newcode12 testing/libfuzzer/fuzzers/ft_new_memory_face_fuzzer.cc:12: FT_Error g_init_freetype_result; On 2016/03/09 17:16:43, inferno wrote: > nit: ...
4 years, 9 months ago (2016-03-10 10:12:55 UTC) #12
mmoroz
The bug I found locally seems to be so old: 1) CVE-2012-1134 by Mateusz (j00ru): ...
4 years, 9 months ago (2016-03-10 10:16:38 UTC) #13
kcc2
4 years, 9 months ago (2016-03-10 21:27:20 UTC) #14
> What for reason we keep such code in Chromium repo?

We should clearly update freetype in chromium to the most recent release.
There were ~50 bugs fixed in the last couple quarters. 
And then we should be fuzzing both the chromium version and tot.

Powered by Google App Engine
This is Rietveld 408576698